← Back

CVE-2008-5523

nvd nist
Published: Dec 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

Affected (1)

1 product
Avast Antivirus
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 4.8.1281.0
Running on/withPlatform Versions
Microsoft
Internet Explorer
Version 6
Microsoft
Internet Explorer
Version 7

Timeline

No history available yet.