← All CVEs

CVE-2008-3010

high · 10

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."

10
CVSS
15.2%
EPSS (exploit prob.)
97th
EPSS percentile
2008-12-10
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
microsoftwindows_media_player6.4
microsoftwindows_2000all versions
microsoftwindows_2003_serverall versions
microsoftwindows_2003_serverall versions
microsoftwindows_2003_serverall versions
microsoftwindows_server_2003all versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-3010