CVE-2008-3466
Microsoft HIS <2006 - Auth Bypass
Title source: llmDescription
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
Exploits (1)
metasploit
WORKING POC
by MC · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/ms/ms08_059_his2006.rb
References (9)
Scores
EPSS
0.8472
EPSS Percentile
99.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (7)
microsoft/host_integration_server_2000
microsoft/host_integration_server_2000
microsoft/host_integration_server_2004
microsoft/host_integration_server_2004
microsoft/host_integration_server_2004
microsoft/host_integration_server_2006
microsoft/host_integration_server_2006
Timeline
Published
Oct 15, 2008
Tracked Since
Feb 18, 2026