CVE-2008-4033
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Affected (4)
Products: Microsoft: Xml Core Services
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 7 | All versions |
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Vista | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows Xp | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 2000 | All versions |
Microsoft Windows 2003 Server | All versions |
Microsoft Windows Server 2008 | All versions |
Microsoft Windows Vista | All versions |
Microsoft Windows Xp | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Expression Web | All versions |
Microsoft Groove | Version 2007 |
Microsoft Office | Version 2003 sp3 |
Microsoft Office Compatibility Pack | All versions |
Microsoft Office Word Viewer | Version 2003 sp3 |
Microsoft Sharepoint Server | Version 2007 |
References (14)
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: secure@microsoft.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.