First published: Wed Nov 26 2008(Updated: )
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
Microsoft Windows 2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5232 is classified as a critical vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2008-5232, it is recommended to apply available security patches from Microsoft for affected versions of Windows NT and 2000.
CVE-2008-5232 impacts systems running Microsoft Windows NT 4.0 and Windows 2000, particularly those using the Windows Media Services ActiveX control.
Yes, CVE-2008-5232 can be exploited remotely by sending specially crafted arguments to the CallHTMLHelp method.
Exploitation of CVE-2008-5232 can enable attackers to execute arbitrary code on affected systems.