First published: Wed Oct 15 2008(Updated: )
Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Internet Explorer | =5.01-sp4 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
Internet Explorer | =6 | |
Any of | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
All of | ||
Internet Explorer | =6-sp1 | |
Microsoft Windows 2000 | =sp4 | |
All of | ||
Internet Explorer | =7 | |
Any of | ||
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =5.01-sp4 | |
Microsoft Windows 2000 | =sp4 | |
Internet Explorer | =6 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp1 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Internet Explorer | =6-sp1 | |
Internet Explorer | =7 | |
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =sp1 | |
Microsoft Windows Vista | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-3474 is classified as a critical vulnerability due to its potential for cross-domain information disclosure.
To remediate CVE-2008-3474, users should update to a patched version of Microsoft Internet Explorer or apply security updates provided by Microsoft.
CVE-2008-3474 affects Microsoft Internet Explorer versions 5.01, 6, and 7.
CVE-2008-3474 can be exploited through crafted HTML documents that bypass cross-domain security policies, allowing attackers to access sensitive information.
While the best remedy is to update Internet Explorer, users may reduce risk by disabling script execution or using alternative browsers not affected by the vulnerability.