7.5
CVSSv2

CVE-2008-3068

Published: 07/07/2008 Updated: 11/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Microsoft Crypto API 5.131.2600.2180 up to and including 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote malicious users to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft groove 2007

microsoft infopath 2003

microsoft outlook 2007

microsoft powerpoint 2003

microsoft visio professional 2007

microsoft visio standard 2007

microsoft access 2007

microsoft office 2007

microsoft office communicator 2007

microsoft project standard 2007

microsoft publisher 2003

microsoft excel 2003

microsoft excel 2007

microsoft frontpage 2003

microsoft onenote 2003

microsoft outlook 2003

microsoft publisher 2007

microsoft sharepoint designer 2007

microsoft infopath 2007

microsoft powerpoint 2007

microsoft project professional 2007

microsoft windows live mail 2008