Lucene search

K
cveMitreCVE-2008-3068
HistoryJul 07, 2008 - 11:41 p.m.

CVE-2008-3068

2008-07-0723:41:00
mitre
web.nvd.nist.gov
33
microsoft crypto api
outlook
windows live mail
office 2007
certificate revocation list
crl
s/mime
e-mail
signed document
remote attack

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.04

Percentile

92.2%

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Affected configurations

Nvd
Node
microsoftaccessMatch2007
OR
microsoftexcelMatch2003
OR
microsoftexcelMatch2007
OR
microsoftfrontpageMatch2003
OR
microsoftgrooveMatch2007
OR
microsoftinfopathMatch2003
OR
microsoftinfopathMatch2007
OR
microsoftofficeMatch2007
OR
microsoftofficeMatch2007sp1
OR
microsoftoffice_communicatorMatch2007
OR
microsoftonenoteMatch2003
OR
microsoftoutlookMatch2003
OR
microsoftoutlookMatch2007
OR
microsoftpowerpointMatch2003
OR
microsoftpowerpointMatch2007
OR
microsoftproject_professionalMatch2007
OR
microsoftproject_standardMatch2007
OR
microsoftpublisherMatch2003
OR
microsoftpublisherMatch2007
OR
microsoftsharepoint_designerMatch2007
OR
microsoftvisio_professionalMatch2007
OR
microsoftvisio_standardMatch2007
OR
microsoftwindows_live_mailMatch2008
VendorProductVersionCPE
microsoftaccess2007cpe:2.3:a:microsoft:access:2007:*:*:*:*:*:*:*
microsoftexcel2003cpe:2.3:a:microsoft:excel:2003:*:*:*:*:*:*:*
microsoftexcel2007cpe:2.3:a:microsoft:excel:2007:*:*:*:*:*:*:*
microsoftfrontpage2003cpe:2.3:a:microsoft:frontpage:2003:*:*:*:*:*:*:*
microsoftgroove2007cpe:2.3:a:microsoft:groove:2007:*:*:*:*:*:*:*
microsoftinfopath2003cpe:2.3:a:microsoft:infopath:2003:*:*:*:*:*:*:*
microsoftinfopath2007cpe:2.3:a:microsoft:infopath:2007:*:*:*:*:*:*:*
microsoftoffice2007cpe:2.3:a:microsoft:office:2007:*:*:*:*:*:*:*
microsoftoffice2007cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:*
microsoftoffice_communicator2007cpe:2.3:a:microsoft:office_communicator:2007:*:*:*:*:*:*:*
Rows per page:
1-10 of 231

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

High

EPSS

0.04

Percentile

92.2%

Related for CVE-2008-3068