CVE-2008-3009
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD
Description
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
Affected (10)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.4 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.1 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2008 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Vista | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 11 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Xp | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.5 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Server 2003 | All versions |
Microsoft Windows Xp | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 2000 | All versions |
Microsoft Windows Xp | All versions |
Related CWEs
References (16)
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
US Government Resource
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.