CVE-2008-2246

Severity
7.8HIGH
EPSS
53.6%
top 2.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 13
Latest updateMay 1

Description

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.

CVSS vector

AV:N/AC:L/C:C/I:N/A:NExploitability: 10.0 | Impact: 6.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gr59-3xq7-cc69: Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Ser2022-05-01
CVEList
CVE-2008-2246: Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Ser2008-08-13
CVE-2008-2246 (HIGH CVSS 7.8) | Microsoft Windows Vista through SP1 | cvebase.io