CVE-2008-3010
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.2%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 15.19% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/windows media player
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/33058
- http://www.securityfocus.com/bid/32654
- http://www.securitytracker.com/id?1021374
- http://www.securitytracker.com/id?1021375
- http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/3388
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-076
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5689
- http://secunia.com/advisories/33058
- http://www.securityfocus.com/bid/32654
- http://www.securitytracker.com/id?1021374
- http://www.securitytracker.com/id?1021375
- http://www.us-cert.gov/cas/techalerts/TA08-344A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2008/3388
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-076
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5689
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.