7.5

CVE-2008-3068

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftAccess Version2007
MicrosoftExcel Version2003
MicrosoftExcel Version2007
MicrosoftFrontpage Version2003
MicrosoftGroove Version2007
MicrosoftInfopath Version2003
MicrosoftInfopath Version2007
MicrosoftOffice Version2007
MicrosoftOffice Version2007 Updatesp1
MicrosoftOffice Communicator Version2007
MicrosoftOnenote Version2003
MicrosoftOutlook Version2003
MicrosoftOutlook Version2007
MicrosoftPowerpoint Version2003
MicrosoftPowerpoint Version2007
MicrosoftProject Standard Version2007
MicrosoftPublisher Version2003
MicrosoftPublisher Version2007
MicrosoftSharepoint Designer Version2007
MicrosoftVisio Professional Version2007
MicrosoftVisio Standard Version2007
MicrosoftWindows Live Mail Version2008
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 12.63% 0.938
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P