SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-0454

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the…

HIGH 9.3EPSS 25.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 25.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Title field of a (1) Dailymotion and possibly (2) Metacafe movie in the Skype video gallery, accessible through a search within the "Add video to chat" dialog, aka "videomood XSS."

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
25.20% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
microsoft/internet explorer · skype technologies/skype
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.