cbcvebase.
CVE-2008-3068
published 2008-07-07

CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by…

PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
17.40%
96.8th percentile
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

Affected

22 ranges
VendorProductVersion rangeFixed in
microsoftaccess
microsoftexcel
microsoftexcel
microsoftfrontpage
microsoftgroove
microsoftinfopath
microsoftinfopath
microsoftoffice
microsoftoffice_communicator
microsoftonenote
microsoftoutlook
microsoftoutlook
microsoftpowerpoint
microsoftpowerpoint
microsoftproject_professional
microsoftproject_standard
microsoftpublisher
microsoftpublisher
microsoftsharepoint_designer
microsoftvisio_professional
microsoftvisio_standard
microsoftwindows_live_mail
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.