CVE-2008-4033
Published Nov 12, 2008
Last updated 6 years ago
Overview
- Description
- Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:xml_core_services:4.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3C9B9BE3-6F83-469E-834F-3E00CFECD8E2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE8F4276-4D97-480D-A542-FE9982FFD765" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2978BF86-5A1A-438E-B81F-F360D0E30C9C" }, { "criteria": "cpe:2.3:o:microsoft:windows_7:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D56B932B-9593-44E2-B610-E4EB2143EB21" }, { "criteria": "cpe:2.3:o:microsoft:windows_7:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7519928D-0FF2-4584-8058-4C7764CD5671" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0C28897B-044A-447B-AD76-6397F8190177" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "32623D48-7000-4C7D-823F-7D2A9841D88C" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "36559BC0-44D7-48B3-86FF-1BFF0257B5ED" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2ACA9287-B475-4AF7-A4DA-A7143CEF9E57" }, { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C162FFF0-1E8F-4DCF-A08F-6C6E324ED878" }, { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0A0D2704-C058-420B-B368-372D1129E914" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CE477A73-4EE4-41E9-8694-5A3D5DC88656" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:xml_core_services:3.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73052210-0B42-46AA-9F28-AAE3E9B6DE87" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE8F4276-4D97-480D-A542-FE9982FFD765" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2978BF86-5A1A-438E-B81F-F360D0E30C9C" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "32623D48-7000-4C7D-823F-7D2A9841D88C" }, { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C162FFF0-1E8F-4DCF-A08F-6C6E324ED878" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CE477A73-4EE4-41E9-8694-5A3D5DC88656" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:xml_core_services:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4170FCB7-274C-4318-B7A1-8F18DE604A2D" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE8F4276-4D97-480D-A542-FE9982FFD765" }, { "criteria": "cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2978BF86-5A1A-438E-B81F-F360D0E30C9C" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "32623D48-7000-4C7D-823F-7D2A9841D88C" }, { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C162FFF0-1E8F-4DCF-A08F-6C6E324ED878" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:x64:*", "vulnerable": false, "matchCriteriaId": "ABBA5D64-4184-4420-B7D0-A4E41359AA5A" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CE477A73-4EE4-41E9-8694-5A3D5DC88656" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:xml_core_services:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9B91A0AA-44C0-4ED8-A7AC-54C9C83FFEFE" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:expression_web:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2876FC23-21A0-4F56-B0D9-11187173F7D7" }, { "criteria": "cpe:2.3:a:microsoft:expression_web:2:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F6761A1C-EC1C-4B00-8126-D58DAB51267A" }, { "criteria": "cpe:2.3:a:microsoft:groove:2007:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "355F60DB-EC9A-4054-8023-BD16D5723C9F" }, { "criteria": "cpe:2.3:a:microsoft:office:2003:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "A332D04D-CC8C-4F68-A261-BA2F2D8EAD1E" }, { "criteria": "cpe:2.3:a:microsoft:office:2007:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "69E6B9EB-D3F7-4C57-BF2F-61664E5C2C7D" }, { "criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:*:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "53DC2480-5B8D-4E96-BD54-17561B1FFE7F" }, { "criteria": "cpe:2.3:a:microsoft:office_compatibility_pack:*:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C0BBD1BF-B54F-41C7-AB52-0B93E647C98D" }, { "criteria": "cpe:2.3:a:microsoft:office_word_viewer:2003:sp3:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B4B148CC-6C58-411B-8503-01F3BE1D5906" }, { "criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "864B622E-B522-4791-AC82-0711130544BA" }, { "criteria": "cpe:2.3:a:microsoft:sharepoint_server:2007:sp1:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CF3C2971-447B-4054-86C6-3169B82E525B" } ], "operator": "OR" } ], "operator": "AND" } ]