10

CVE-2008-3009

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows Media Player Version6.4
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Editionpro_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionpro_x64
   MicrosoftWindows Xp Updatesp3
MicrosoftWindows Media Format Runtime Version7.1
   MicrosoftWindows 2000 Updatesp4
MicrosoftWindows Media Services Version4.1
   MicrosoftWindows 2000 Updatesp4
MicrosoftWindows Media Services Version9
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Updatesp3
MicrosoftWindows Media Services Version2008
   MicrosoftWindows Server 2008 Editionx32
   MicrosoftWindows Server 2008 Editionx64
MicrosoftWindows Media Format Runtime Version11
   MicrosoftWindows Server 2008 Editionx32
   MicrosoftWindows Server 2008 Editionx64
   MicrosoftWindows Vista Editionx64
   MicrosoftWindows Vista Updatesp1
   MicrosoftWindows Vista Versiongold
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionpro_x64
   MicrosoftWindows Xp Updatesp3
MicrosoftWindows Media Format Runtime Version11 Editionx64
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Editionpro_x64
   MicrosoftWindows Xp Updatesp2 Editionpro_x64
MicrosoftWindows Media Format Runtime Version9.5 Editionx64
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Updatesp2 Editionpro_x64
MicrosoftWindows Media Format Runtime Version9.5
   MicrosoftWindows Server 2003
   MicrosoftWindows Server 2003 Updatesp1
   MicrosoftWindows Server 2003 Updatesp2
   MicrosoftWindows Xp Editionx64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionpro_x64
   MicrosoftWindows Xp Updatesp3
MicrosoftWindows Media Format Runtime Version9
   MicrosoftWindows 2000 Updatesp4
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 52.28% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C