CVE-2008-3008

EXPLOITED

Microsoft Windows Media Encoder - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16521
exploitdb WORKING POC VERIFIED
by haluznik · htmlremotewindows
https://www.exploit-db.com/exploits/6454
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/ms08_053_mediaencoder.rb

Scores

EPSS 0.8110
EPSS Percentile 99.2%

Details

VulnCheck KEV 2010-05-01
CWE
CWE-119
Status published
Products (5)
microsoft/windows_2000
microsoft/windows_2003_server (4 CPE variants)
microsoft/windows_media_encoder 9_series
microsoft/windows-nt xp sp3
microsoft/windows_xp (2 CPE variants)
Published Sep 11, 2008
Tracked Since Feb 18, 2026