CVE-2008-1448
published 2008-08-13CVE-2008-1448: The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet…
PriorityP335high7.1CVSS 2.0
AVNACMAuNCCINAN
EPSS
26.63%
97.8th percentile
The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in conjunction with a redirection, aka "URL Parsing Cross-Domain Information Disclosure Vulnerability."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | outlook_express | — | — |
| microsoft | outlook_express | — | — |
| microsoft | windows_vista | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh3v-wwhj-j4pq: Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2010-0555 [HIGH] GHSA-mh3v-wwhj-j4pq: Microsoft Internet Explorer 5
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.
GHSA
GHSA-93vc-2h9g-v2wq: Microsoft Internet Explorer 5
ghsa_unreviewed·2022-05-02·CVSS 7.1
CVE-2010-0255 [HIGH] GHSA-93vc-2h9g-v2wq: Microsoft Internet Explorer 5
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
GHSA
GHSA-8xj3-mf49-rfmm: The MHTML protocol handler in a component of Microsoft Outlook Express 5
ghsa_unreviewed·2022-05-01
CVE-2008-1448 [HIGH] GHSA-8xj3-mf49-rfmm: The MHTML protocol handler in a component of Microsoft Outlook Express 5
The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in conjunction with a redirection, aka "URL Parsing Cross-Domain Information Disclosure Vulnerability."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=121915960406986&w=2http://secunia.com/advisories/31415http://www.coresecurity.com/content/internet-explorer-zone-elevationhttp://www.securityfocus.com/archive/1/495458/100/0/threadedhttp://www.securityfocus.com/bid/30585http://www.securitytracker.com/id?1020679http://www.securitytracker.com/id?1020680http://www.us-cert.gov/cas/techalerts/TA08-225A.htmlhttp://www.vupen.com/english/advisories/2008/2352https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5886http://marc.info/?l=bugtraq&m=121915960406986&w=2http://secunia.com/advisories/31415http://www.coresecurity.com/content/internet-explorer-zone-elevationhttp://www.securityfocus.com/archive/1/495458/100/0/threadedhttp://www.securityfocus.com/bid/30585http://www.securitytracker.com/id?1020679http://www.securitytracker.com/id?1020680http://www.us-cert.gov/cas/techalerts/TA08-225A.htmlhttp://www.vupen.com/english/advisories/2008/2352https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-048https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5886
2008-08-13
Published