CVE-2008-4032
published 2008-12-10CVE-2008-4032: Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
47.91%
98.7th percentile
Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for administrative functions, which allows remote attackers to cause a denial of service (server load), obtain sensitive information, and "create scripts that would run in the context of the site" via requests to administrative URIs, aka "Access Control Vulnerability."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_sharepoint_server | — | — |
| microsoft | search_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urladministrative URIs on Microsoft Office SharePoint Server 2007 / Search Server 2008
- →Monitor for unauthenticated or unauthorized HTTP requests targeting SharePoint/Search Server administrative URIs, which may indicate exploitation of the access control bypass. ↗
- →Look for abnormal server load patterns or unexpected script execution in the context of the SharePoint site, which are behavioral indicators of this vulnerability being exploited. ↗
- ·Vulnerability affects both the Gold (RTM) and SP1 releases of Microsoft Office SharePoint Server 2007, as well as Microsoft Search Server 2008; detection/patching scope must cover all these versions. ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/33063http://www.securitytracker.com/id?1021367http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlhttp://www.vupen.com/english/advisories/2008/3389https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-077https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5774http://secunia.com/advisories/33063http://www.securitytracker.com/id?1021367http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlhttp://www.vupen.com/english/advisories/2008/3389https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-077https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5774
2008-12-10
Published