PT-2008-5348 · Microsoft · Xml Core Services+3

Stefano Di Paola

·

Published

2008-11-12

·

Updated

2018-10-12

·

CVE-2008-4033

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft XML Core Services versions 3.0 through 6.0
Description The issue allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, such as the Transfer-Encoding field. This could enable an attacker to read data from a Web page in another domain in Internet Explorer if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail.
Recommendations For Microsoft XML Core Services versions 3.0 through 6.0, consider disabling the handling of Transfer-Encoding headers as a temporary workaround until a patch is available. Restrict access to specially crafted Web sites and HTML e-mail to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4033

Affected Products

Internet Explorer
Xml Core Services
Office
Office Visio