← All CVEs

CVE-2008-3068

high · 7.5

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

7.5
CVSS
17.4%
EPSS (exploit prob.)
97th
EPSS percentile
2008-07-07
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
microsoftaccess2007
microsoftexcel2003
microsoftexcel2007
microsoftfrontpage2003
microsoftgroove2007
microsoftinfopath2003
microsoftinfopath2007
microsoftoffice2007
microsoftoffice2007
microsoftoffice_communicator2007
microsoftonenote2003
microsoftoutlook2003
microsoftoutlook2007
microsoftpowerpoint2003
microsoftpowerpoint2007
microsoftproject_professional2007
microsoftproject_standard2007
microsoftpublisher2003
microsoftpublisher2007
microsoftsharepoint_designer2007
microsoftvisio_professional2007
microsoftvisio_standard2007
microsoftwindows_live_mail2008

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-3068