CVE-2008-4033

Microsoft XML Core Services 3.0-6.0 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4033. PoCs published by Jerome Athias.

AI-analyzed exploit summary This exploit leverages an XML External Entity (XXE) vulnerability in Microsoft XML Core Services (MSXML) via ActiveX. It attempts to load an external DTD from a remote URL, which could lead to information disclosure or further exploitation.

Description

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jerome Athias · htmlremotewindows
https://www.exploit-db.com/exploits/7196

This exploit leverages an XML External Entity (XXE) vulnerability in Microsoft XML Core Services (MSXML) via ActiveX. It attempts to load an external DTD from a remote URL, which could lead to information disclosure or further exploitation.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Microsoft XML Core Services (MSXML) 3.0
No auth needed
Prerequisites: Victim must open the HTML file in a browser with ActiveX enabled · Msxml2.DOMDocument.3.0 must be available
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=122703006921213&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA08-316A.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3111
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1021164
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32204

Scores

EPSS 0.2775
EPSS Percentile 97.8%

Details

CWE
CWE-200
Status published
Products (4)
microsoft/xml_core_services 4.0
microsoft/xml_core_services 3.0
microsoft/xml_core_services 6.0
microsoft/xml_core_services 5.0
Published Nov 12, 2008
Tracked Since Feb 18, 2026