// For flags

CVE-2008-1438

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.

Vulnerabilidad no especificada en la Máquina de Protección de Malware de Microsoft (mpengine.dll) versiones 1.1.3520.0 y 0.1.13.192, tal y como se usa en múltiples productos de Microsoft, permite a atacantes según contexto provocar una denegación de Servicio (agotamiento de espacio en disco) a través de “estructuras de datos manipuladas” que provocan la creación de ficheros grandes temporales, una vulnerabilidad diferente a la CVE-2008-1438.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-03-21 CVE Reserved
  • 2008-05-13 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-11-23 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Microsoft
Search vendor "Microsoft"
Antigen For Exchange
Search vendor "Microsoft" for product "Antigen For Exchange"
*-
Affected
Microsoft
Search vendor "Microsoft"
Antigen For Smtp Gateway
Search vendor "Microsoft" for product "Antigen For Smtp Gateway"
*-
Affected
Microsoft
Search vendor "Microsoft"
Diagnostics And Recovery Toolkit
Search vendor "Microsoft" for product "Diagnostics And Recovery Toolkit"
6.0
Search vendor "Microsoft" for product "Diagnostics And Recovery Toolkit" and version "6.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Forefront Client Security
Search vendor "Microsoft" for product "Forefront Client Security"
*-
Affected
Microsoft
Search vendor "Microsoft"
Forefront Security For Exchange Server
Search vendor "Microsoft" for product "Forefront Security For Exchange Server"
*-
Affected
Microsoft
Search vendor "Microsoft"
Forefront Security For Sharepoint
Search vendor "Microsoft" for product "Forefront Security For Sharepoint"
*-
Affected
Microsoft
Search vendor "Microsoft"
Malware Protection Engine
Search vendor "Microsoft" for product "Malware Protection Engine"
0.1.13.192
Search vendor "Microsoft" for product "Malware Protection Engine" and version "0.1.13.192"
-
Affected
Microsoft
Search vendor "Microsoft"
Malware Protection Engine
Search vendor "Microsoft" for product "Malware Protection Engine"
1.1.3520.0
Search vendor "Microsoft" for product "Malware Protection Engine" and version "1.1.3520.0"
-
Affected
Microsoft
Search vendor "Microsoft"
Windows Defender
Search vendor "Microsoft" for product "Windows Defender"
*-
Affected
Microsoft
Search vendor "Microsoft"
Windows Live Onecare
Search vendor "Microsoft" for product "Windows Live Onecare"
*-
Affected