CVE-2008-3068: High severity microsoft access 2010 vulnerability
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3068?
CVE-2008-3068 is rated as a medium severity vulnerability due to its potential for exploitation through malicious S/MIME emails and documents.
How do I fix CVE-2008-3068?
To mitigate CVE-2008-3068, ensure that your Microsoft software is updated to the latest security patches provided by Microsoft.
What software is affected by CVE-2008-3068?
CVE-2008-3068 affects several Microsoft products including Outlook 2003, Outlook 2007, Windows Live Mail 2008, and multiple versions of Microsoft Office applications.
Can CVE-2008-3068 be exploited remotely?
Yes, attackers can exploit CVE-2008-3068 remotely by embedding malicious URLs in S/MIME emails or signed documents.
What types of attacks can leverage CVE-2008-3068?
CVE-2008-3068 can be leveraged for attacks involving unauthorized access or manipulation of data by exploiting certificate revocation list checks.