← Back

CVE-2008-4033

nvd nist
Published: Nov 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

Affected (4)

1 product
Xml Core Services
Configuration A
1 vulnerable · 6 platform
Vulnerable SoftwareAffected Versions
Version 4.0
Running on/withPlatform Versions
Microsoft
Windows 7
All versions
Microsoft
Windows 7
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Server 2008
Version r2
Microsoft
Windows Server 2008
Version r2 sp1
Microsoft
Windows Vista
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.0
Running on/withPlatform Versions
Microsoft
Windows Xp
All versions
Configuration C
1 vulnerable · 7 platform
Vulnerable SoftwareAffected Versions
Version 6.0
Running on/withPlatform Versions
Microsoft
Windows 2000
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows 2003 Server
All versions
Microsoft
Windows Server 2008
All versions
Microsoft
Windows Vista
All versions
Microsoft
Windows Xp
All versions
Microsoft
Windows Xp
All versions
Configuration D
1 vulnerable · 10 platform
Vulnerable SoftwareAffected Versions
Version 5.0
Running on/withPlatform Versions
Microsoft
Expression Web
All versions
Microsoft
Expression Web
Version 2
Microsoft
Groove
Version 2007
Microsoft
Office
Version 2003 sp3
Microsoft
Office
Version 2007 sp1
Microsoft
Office Compatibility Pack
All versions
Microsoft
Office Compatibility Pack
All versions
Microsoft
Office Word Viewer
Version 2003 sp3
Microsoft
Sharepoint Server
Version 2007
Microsoft
Sharepoint Server
Version 2007 sp1

References (14)

Source: secure@microsoft.com
Source: secure@microsoft.com
Patch
Source: secure@microsoft.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.