First published: Mon Jul 07 2008(Updated: )
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Access | =2007 | |
Microsoft Excel for Mac | =2003 | |
Microsoft Excel for Mac | =2007 | |
Microsoft Office FrontPage | =2003 | |
Microsoft Office Groove Server | =2007 | |
Microsoft InfoPath | =2003 | |
Microsoft InfoPath | =2007 | |
Microsoft Office | =2007 | |
Microsoft Office | =2007-sp1 | |
Microsoft Office Communicator | =2007 | |
Microsoft OneNote for Mac | =2003 | |
Microsoft Outlook | =2003 | |
Microsoft Outlook | =2007 | |
Microsoft PowerPoint | =2003 | |
Microsoft PowerPoint | =2007 | |
Microsoft Project Professional | =2007 | |
Microsoft Project | =2007 | |
Microsoft Publisher | =2003 | |
Microsoft Publisher | =2007 | |
Microsoft SharePoint Designer | =2007 | |
Microsoft Visio Professional | =2007 | |
Microsoft Visio Standard | =2007 | |
Microsoft Windows Live Hotmail | =2008 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3068 is rated as a medium severity vulnerability due to its potential for exploitation through malicious S/MIME emails and documents.
To mitigate CVE-2008-3068, ensure that your Microsoft software is updated to the latest security patches provided by Microsoft.
CVE-2008-3068 affects several Microsoft products including Outlook 2003, Outlook 2007, Windows Live Mail 2008, and multiple versions of Microsoft Office applications.
Yes, attackers can exploit CVE-2008-3068 remotely by embedding malicious URLs in S/MIME emails or signed documents.
CVE-2008-3068 can be leveraged for attacks involving unauthorized access or manipulation of data by exploiting certificate revocation list checks.