CVE-2008-1435: Code Injection
Published Jul 8, 2008
·Updated
Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."
Affected Software
2 affected components
Microsoft Windows Vista
Microsoft Windows-nt=2008
Event History
Jul 8, 2008
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-1435?
CVE-2008-1435 has a high severity level due to its potential to allow remote code execution.
2
How do I fix CVE-2008-1435?
To mitigate CVE-2008-1435, it is recommended to update to service packs or patches provided by Microsoft.
3
Which software versions are affected by CVE-2008-1435?
CVE-2008-1435 affects Microsoft Windows Vista up to SP1 and Windows Server 2008.
4
Can CVE-2008-1435 be exploited without user interaction?
Exploitation of CVE-2008-1435 requires user interaction, such as opening a crafted saved-search file.
5
What type of attack does CVE-2008-1435 represent?
CVE-2008-1435 represents a user-assisted remote code execution attack targeting Windows Explorer.