4.3

CVE-2008-4033

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Xml Core Services Version 4.0
   Microsoft ≫ Windows 2000 Update sp4
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows 2003 Server Update sp2
   Microsoft ≫ Windows 7
   Microsoft ≫ Windows 7 Update sp1
   Microsoft ≫ Windows Server 2008 Update sp2
   Microsoft ≫ Windows Server 2008 Version -
   Microsoft ≫ Windows Server 2008 Version r2
   Microsoft ≫ Windows Server 2008 Version r2 Update sp1
   Microsoft ≫ Windows Vista Update sp1
   Microsoft ≫ Windows Vista Update sp2
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 3.0
   Microsoft ≫ Windows 2000 Update sp4
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows 2003 Server Update sp2
   Microsoft ≫ Windows Server 2008 Version -
   Microsoft ≫ Windows Vista Update sp1
   Microsoft ≫ Windows Xp Update sp2
   Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 6.0
   Microsoft ≫ Windows 2000 Update sp4
   Microsoft ≫ Windows 2003 Server Update sp1
   Microsoft ≫ Windows 2003 Server Update sp2
   Microsoft ≫ Windows Server 2008 Version -
   Microsoft ≫ Windows Vista Update sp1
   Microsoft ≫ Windows Xp Update sp2 HwPlatform x64
   Microsoft ≫ Windows Xp Update sp3
Microsoft ≫ Xml Core Services Version 5.0
   Microsoft ≫ Expression Web
   Microsoft ≫ Expression Web Version 2
   Microsoft ≫ Groove Version 2007
   Microsoft ≫ Office Version 2003 Update sp3
   Microsoft ≫ Office Version 2007 Update sp1
   Microsoft ≫ Office Compatibility Pack
   Microsoft ≫ Office Compatibility Pack Update sp1
   Microsoft ≫ Office Word Viewer Version 2003 Update sp3
   Microsoft ≫ Sharepoint Server Version 2007
   Microsoft ≫ Sharepoint Server Version 2007 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 27.75% 0.978
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://marc.info/?l=bugtraq&m=122703006921213&w=2
http://securitytracker.com/id?1021164
http://www.us-cert.gov/cas/techalerts/TA08-316A.html
Third Party Advisory
US Government Resource
http://www.vupen.com/english/advisories/2008/3111
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069
http://www.securityfocus.com/bid/32204
Patch
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847