Lucene search

K
cveMicrosoftCVE-2008-3009
HistoryDec 10, 2008 - 2:00 p.m.

CVE-2008-3009

2008-12-1014:00:00
CWE-255
microsoft
web.nvd.nist.gov
31
microsoft
windows media player
spn vulnerability
cve-2008-3009
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.114

Percentile

95.3%

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka โ€œSPN Vulnerability.โ€

Affected configurations

Nvd
Node
microsoftwindows_media_playerMatch6.4
AND
microsoftwindows_2000sp4
OR
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp1
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xppro_x64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2pro_x64
OR
microsoftwindows_xpsp3
Node
microsoftwindows_media_format_runtimeMatch7.1
AND
microsoftwindows_2000sp4
Node
microsoftwindows_media_servicesMatch4.1
AND
microsoftwindows_2000sp4
Node
microsoftwindows_media_servicesMatch9
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp1
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp3
Node
microsoftwindows_media_servicesMatch2008
AND
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
Node
microsoftwindows_media_format_runtimeMatch11
AND
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_vistax64
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistaMatchgold
OR
microsoftwindows_xpx64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2pro_x64
OR
microsoftwindows_xpsp3
Node
microsoftwindows_media_format_runtimeMatch11x64
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xppro_x64
OR
microsoftwindows_xpsp2pro_x64
Node
microsoftwindows_media_format_runtimeMatch9.5x64
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpx64
OR
microsoftwindows_xpsp2pro_x64
Node
microsoftwindows_media_format_runtimeMatch9.5
AND
microsoftwindows_server_2003
OR
microsoftwindows_server_2003sp1
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpx64
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2pro_x64
OR
microsoftwindows_xpsp3
Node
microsoftwindows_media_format_runtimeMatch9
AND
microsoftwindows_2000sp4
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp3
VendorProductVersionCPE
microsoftwindows_media_player6.4cpe:2.3:a:microsoft:windows_media_player:6.4:*:*:*:*:*:*:*
microsoftwindows_2000*cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*
microsoftwindows_server_2003*cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:*:pro_x64:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:pro_x64:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*
microsoftwindows_media_format_runtime7.1cpe:2.3:a:microsoft:windows_media_format_runtime:7.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 241

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.114

Percentile

95.3%