CVE-2008-2306: Critical severity microsoft windows vista vulnerability
Published Jun 23, 2008
·Updated
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTIONSHELLEXECUTEHIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute arbitrary files.
Affected Software
9 affected components
Microsoft Windows Vista
Microsoft Windows XP
Safari<=3.1.1
Safari=3.0
Safari=3.0.1
Safari=3.0.2
Safari=3.0.3
Safari=3.0.4
Safari=3.1
Remediation
Event History
Jun 23, 2008
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
08:41 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2008-2306?
CVE-2008-2306 is considered a moderate severity vulnerability.
2
How do I fix CVE-2008-2306?
To fix CVE-2008-2306, upgrade Apple Safari to version 3.1.2 or later.
3
What software is affected by CVE-2008-2306?
CVE-2008-2306 affects Apple Safari versions prior to 3.1.2 on Windows.
4
What type of attack does CVE-2008-2306 enable?
CVE-2008-2306 allows remote attackers to bypass access restrictions and execute arbitrary files.
5
How does CVE-2008-2306 exploit the system?
CVE-2008-2306 exploits improper interpretation of the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting.