Lucene search

K
cve[email protected]CVE-2008-1089
HistoryApr 08, 2008 - 11:05 p.m.

CVE-2008-1089

2008-04-0823:05:00
CWE-94
web.nvd.nist.gov
60
cve-2008-1089
microsoft visio
vulnerability
user-assisted
remote execution
crafted object header
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.566 Medium

EPSS

Percentile

97.7%

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka β€œVisio Object Header Vulnerability.”

Affected configurations

NVD
Node
microsoftofficeMatch2003sp2
OR
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2007
OR
microsoftofficeMatch2007_sp1
OR
microsoftofficeMatchxpsp2
OR
microsoftvisioMatch2002sp2
OR
microsoftvisioMatch2003sp1
OR
microsoftvisioMatch2003_sp3
OR
microsoftvisioMatch2007
OR
microsoftvisioMatch2007_sp1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.3 High

AI Score

Confidence

Low

0.566 Medium

EPSS

Percentile

97.7%