PT-2008-5348 · Microsoft · Xml Core Services+3
Stefano Di Paola
·
Published
2008-11-12
·
Updated
2018-10-12
·
CVE-2008-4033
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft XML Core Services versions 3.0 through 6.0
Description
The issue allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, such as the
Transfer-Encoding field. This could enable an attacker to read data from a Web page in another domain in Internet Explorer if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail.Recommendations
For Microsoft XML Core Services versions 3.0 through 6.0, consider disabling the handling of
Transfer-Encoding headers as a temporary workaround until a patch is available. Restrict access to specially crafted Web sites and HTML e-mail to minimize the risk of exploitation.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Xml Core Services
Office
Office Visio