CVE-2008-3068

Microsoft Crypto API <6.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

References (14)

Core 14
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3978
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/494101/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28548
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019736
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019738
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019737
Various Sources x_refsource_misc
https://www.cynops.de/techzone/http_over_x509.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/493947/100/0/threaded

Scores

EPSS 0.1740
EPSS Percentile 96.8%

Details

Status published
Products (22)
microsoft/access 2007
microsoft/excel 2003
microsoft/excel 2007
microsoft/frontpage 2003
microsoft/groove 2007
microsoft/infopath 2003
microsoft/infopath 2007
microsoft/office 2007 (2 CPE variants)
microsoft/office_communicator 2007
microsoft/onenote 2003
... and 12 more
Published Jul 07, 2008
Tracked Since Feb 18, 2026