Lucene search

K
cve[email protected]CVE-2008-1092
HistoryMar 25, 2008 - 4:44 p.m.

CVE-2008-1092

2008-03-2516:44:00
CWE-119
web.nvd.nist.gov
29
cve-2008-1092
buffer overflow
msjet40.dll
microsoft jet database engine
arbitrary code
word file

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.842 High

EPSS

Percentile

98.5%

Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.

Affected configurations

NVD
Node
microsoftwindows_2000Match-
OR
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_xpMatch-
AND
microsoftwordMatch2000sp3
OR
microsoftwordMatch2002sp3
OR
microsoftwordMatch2003sp2
OR
microsoftwordMatch2003_sp3
OR
microsoftwordMatch2007
OR
microsoftwordMatch2007_sp1

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

Low

0.842 High

EPSS

Percentile

98.5%