8.5
CVE-2008-4269
- EPSS 20.52%
- Veröffentlicht 10.12.2008 14:00:01
- Zuletzt bearbeitet 16.06.2026 22:57:31
- Erkennungen
The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2008 Edition itanium
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Vista Edition x64
Microsoft ≫ Windows Vista Update gold
Microsoft ≫ Windows Vista Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 20.52% | 0.972 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.5 | 6.8 | 10 |
AV:N/AC:M/Au:S/C:C/I:C/A:C
|
http://www.us-cert.gov/cas/techalerts/TA08-344A.html
http://secunia.com/advisories/33053
http://www.securitytracker.com/id?1021366
http://www.vupen.com/english/advisories/2008/3387
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-075
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6110