CVE-2008-4033
published 2008-11-12CVE-2008-4033: Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products…
PriorityP431medium4.3CVSS 2.0
AVNACMAuNCPINAN
EXPLOIT
EPSS
27.75%
97.9th percentile
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
| microsoft | xml_core_services | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit uses ActiveXObject instantiation of Msxml2.DOMDocument.3.0 to load a remote DTD cross-domain, which is the attack primitive for CVE-2008-4033/MS08-069; monitor for script-initiated creation of this ProgID loading remote URLs. ↗
- →The incomplete fix for CVE-2008-4033 left Set-Cookie2 HTTP response headers accessible via XMLHttpRequest, bypassing HTTPOnly; monitor XMLHttpRequest responses for Set-Cookie2 header exposure from cross-origin requests. ↗
- ·The exploit payload references a remote DTD hosted on milw0rm.com, which is an attacker-controlled URL used at time of publication (2008-11-23); the domain is no longer active/malicious but illustrates the cross-domain DTD loading vector. ↗
- ·CVE-2009-0419 is documented as a follow-on incomplete fix for CVE-2008-4033; detections targeting CVE-2008-4033 should also account for the residual Set-Cookie2 bypass described in CVE-2009-0419. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-24qg-x6r4-72m5: Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict ac
ghsa_unreviewed·2022-05-02·CVSS 4.3
CVE-2009-0419 [MEDIUM] GHSA-24qg-x6r4-72m5: Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict ac
Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.
GHSA
GHSA-65h5-7wf2-rcj3: Cross-domain vulnerability in Microsoft XML Core Services 3
ghsa_unreviewed·2022-05-02
CVE-2008-4033 [MEDIUM] CWE-200 GHSA-65h5-7wf2-rcj3: Cross-domain vulnerability in Microsoft XML Core Services 3
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=122703006921213&w=2http://securitytracker.com/id?1021164http://www.securityfocus.com/bid/32204http://www.us-cert.gov/cas/techalerts/TA08-316A.htmlhttp://www.vupen.com/english/advisories/2008/3111https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847http://marc.info/?l=bugtraq&m=122703006921213&w=2http://securitytracker.com/id?1021164http://www.securityfocus.com/bid/32204http://www.us-cert.gov/cas/techalerts/TA08-316A.htmlhttp://www.vupen.com/english/advisories/2008/3111https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-069https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5847
2008-11-12
Published