← Back

CVE-2008-5526

nvd nist
Published: Dec 12, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

Affected (1)

Products: Drweb: Anti Virus
1 product
Anti Virus
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 4.44.0.09170
Running on/withPlatform Versions
Microsoft
Internet Explorer
Version 6
Microsoft
Internet Explorer
Version 7

Timeline

No history available yet.