CVE-2008-1444
Microsoft DirectX SAMI File Format Name Parsing Stack Overflow Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."
Desbordamiento de búfer basado en pila en Microsoft DirectX 7.0 y 8.1 o en Windows 2000 SP4 permite a atacantes remotos ejecutar código de su elección a través de un archivo Synchronized Accessible Media Interchange (SAMI) con parámetros manipulados para una variable Class Name, también conocida como la "Vulnerabilidad SAMI Format Parsing"
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists in the parsing of SAMI files. When handling the properties of a "Class Name" variable a lack of bounds checking can result in a stack overflow. Successful exploitation can lead to remote code execution under the credentials of the logged in user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-03-21 CVE Reserved
- 2008-06-10 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/3937 | Third Party Advisory | |
http://securitytracker.com/id?1020223 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/493250/100/0/threaded | Mailing List | |
http://www.us-cert.gov/cas/techalerts/TA08-162B.html | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/1780 | Broken Link | |
http://www.zerodayinitiative.com/advisories/ZDI-08-040 | Third Party Advisory | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5562 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30579 | 2018-10-12 | |
http://www.securityfocus.com/bid/29578 | 2018-10-12 |
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=121380194923597&w=2 | 2018-10-12 | |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-033 | 2018-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows-nt Search vendor "Microsoft" for product "Windows-nt" | xp Search vendor "Microsoft" for product "Windows-nt" and version "xp" | sp3 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | sp1 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | sp1, itanium |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | sp2 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | sp2, itanium |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2003 Server Search vendor "Microsoft" for product "Windows 2003 Server" | * | sp2, x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 9.0 Search vendor "Microsoft" for product "Directx" and version "9.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Xp Search vendor "Microsoft" for product "Windows Xp" | * | sp2, x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 10.0 Search vendor "Microsoft" for product "Directx" and version "10.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows-nt Search vendor "Microsoft" for product "Windows-nt" | 2008 Search vendor "Microsoft" for product "Windows-nt" and version "2008" | itanium |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 10.0 Search vendor "Microsoft" for product "Directx" and version "10.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows-nt Search vendor "Microsoft" for product "Windows-nt" | 2008 Search vendor "Microsoft" for product "Windows-nt" and version "2008" | x32 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 10.0 Search vendor "Microsoft" for product "Directx" and version "10.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows-nt Search vendor "Microsoft" for product "Windows-nt" | 2008 Search vendor "Microsoft" for product "Windows-nt" and version "2008" | x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 10.0 Search vendor "Microsoft" for product "Directx" and version "10.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Vista Search vendor "Microsoft" for product "Windows Vista" | * | x64 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 7.0 Search vendor "Microsoft" for product "Directx" and version "7.0" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Safe
|
Microsoft Search vendor "Microsoft" | Directx Search vendor "Microsoft" for product "Directx" | 8.1 Search vendor "Microsoft" for product "Directx" and version "8.1" | - |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | * | sp4 |
Safe
|