CVE-2008-5828Sensitive Information Exposure in Microsoft Windows Live Messenger

Severity
5.0MEDIUMNVD
EPSS
17.9%
top 4.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 14

Description

Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2) IPv4Internal-Addrs, and (3) IPv4Internal-Port header fields.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-j27v-pj6v-rp49: Microsoft Windows Live Messenger Client 82022-05-14
CVEList
CVE-2008-5828: Microsoft Windows Live Messenger Client 82009-01-02
CVE-2008-5828 — Sensitive Information Exposure | cvebase