CVE Vulnerabilities

CVE-2008-3068

Published: Jul 07, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Affected Software

Name Vendor Start Version End Version
Access Microsoft 2007 (including) 2007 (including)
Excel Microsoft 2003 (including) 2003 (including)
Excel Microsoft 2007 (including) 2007 (including)
Frontpage Microsoft 2003 (including) 2003 (including)
Groove Microsoft 2007 (including) 2007 (including)
Infopath Microsoft 2003 (including) 2003 (including)
Infopath Microsoft 2007 (including) 2007 (including)
Office Microsoft 2007 (including) 2007 (including)
Office Microsoft 2007-sp1 (including) 2007-sp1 (including)
Office_communicator Microsoft 2007 (including) 2007 (including)
Onenote Microsoft 2003 (including) 2003 (including)
Outlook Microsoft 2003 (including) 2003 (including)
Outlook Microsoft 2007 (including) 2007 (including)
Powerpoint Microsoft 2003 (including) 2003 (including)
Powerpoint Microsoft 2007 (including) 2007 (including)
Project_professional Microsoft 2007 (including) 2007 (including)
Project_standard Microsoft 2007 (including) 2007 (including)
Publisher Microsoft 2003 (including) 2003 (including)
Publisher Microsoft 2007 (including) 2007 (including)
Sharepoint_designer Microsoft 2007 (including) 2007 (including)
Visio_professional Microsoft 2007 (including) 2007 (including)
Visio_standard Microsoft 2007 (including) 2007 (including)
Windows_live_mail Microsoft 2008 (including) 2008 (including)

References