CVE-2008-5232
Microsoft Windows Media Services 'nskey.dll' 4.1 - ActiveX Control Remote Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Desbordamiento de búfer en el método CallHTMLHelp en el control ActiveX Microsoft Windows Media Services en nskey.dll 4.1.00.3917 en Windows Media Services en Microsoft Windows NT y 2000, y Avaya Media y Message Application servers, permite a atacantes remotos ejecutar código de su elección mediante un argumento largo. NOTA: el origen de esta información es desconocido; los detalles se han obtenido únicamente de información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-08-22 First Exploit
- 2008-11-25 CVE Reserved
- 2008-11-26 CVE Published
- 2023-12-09 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://securitytracker.com/id?1020733 | Third Party Advisory | |
http://www.securityfocus.com/bid/30814 | Third Party Advisory | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/44629 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/32294 | 2008-08-22 | |
http://packetstormsecurity.org/0808-exploits/wms-overflow.txt | 2024-08-07 | |
http://www.securityfocus.com/data/vulnerabilities/exploits/30814.html.txt | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Windows 2000 Search vendor "Microsoft" for product "Windows 2000" | - | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Windows Nt Search vendor "Microsoft" for product "Windows Nt" | 4.0 Search vendor "Microsoft" for product "Windows Nt" and version "4.0" | - |
Affected
|