Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2008-07-07 23:41
Updated : 2018-10-11 20:45
NVD link : CVE-2008-3068
Mitre link : CVE-2008-3068
CVE.ORG link : CVE-2008-3068
JSON object : View
Products Affected
microsoft
- office
- visio_professional
- frontpage
- visio_standard
- project_professional
- excel
- access
- publisher
- onenote
- project_standard
- sharepoint_designer
- infopath
- windows_live_mail
- groove
- powerpoint
- office_communicator
- outlook
CWE