← Back

CVE-2008-5521

nvd nist
Published: Dec 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

Affected (2)

Products: Free Av: Antivir
1 product
Antivir
Configuration A
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Free Av
Version 7.8.1.28
Version 7.9.0.36
Running on/withPlatform Versions
Microsoft
Internet Explorer
Version 6
Microsoft
Internet Explorer
Version 7

Timeline

No history available yet.