CVE-2008-4269
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 21%
exploitation probability
21%top 3% of all CVEs
observed exploitation
nono source reports it
The search-ms protocol handler in Windows Explorer in Microsoft Windows Vista Gold and SP1 and Server 2008 uses untrusted parameter data obtained from incorrect parsing, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Windows Search Parsing Vulnerability."
Affected products
n/a · n/aReferences
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-075http://secunia.com/advisories/33053https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6110http://www.securitytracker.com/id?1021366http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlhttp://www.vupen.com/english/advisories/2008/3387