CVE-2008-3010: Infoleak
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3010?
CVE-2008-3010 is rated as a medium severity vulnerability that can lead to credential theft and remote code execution.
How do I fix CVE-2008-3010?
To mitigate CVE-2008-3010, ensure that you update to the latest version of Windows Media Player or apply relevant security patches provided by Microsoft.
What systems are affected by CVE-2008-3010?
CVE-2008-3010 primarily affects Microsoft Windows Media Player versions 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9.
What are the consequences of exploiting CVE-2008-3010?
Exploitation of CVE-2008-3010 can allow attackers to capture NTLM credentials and execute arbitrary code on affected systems.
Is there a workaround for CVE-2008-3010?
A temporary workaround for CVE-2008-3010 is to disable the ability to automatically associate ISATAP addresses with the Local Intranet zone.