cbcvebase.
CVE-2008-3068
published 2008-07-07

CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Affected

22 ranges
VendorProductVersion rangeFixed in
microsoftaccess
microsoftexcel
microsoftexcel
microsoftfrontpage
microsoftgroove
microsoftinfopath
microsoftinfopath
microsoftoffice
microsoftoffice_communicator
microsoftonenote
microsoftoutlook
microsoftoutlook
microsoftpowerpoint
microsoftpowerpoint
microsoftproject_professional
microsoftproject_standard
microsoftpublisher
microsoftpublisher
microsoftsharepoint_designer
microsoftvisio_professional
microsoftvisio_standard
microsoftwindows_live_mail