CVE-2008-1092
Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- February 28, 2008
- Published Date
- March 25, 2008
- Last Updated
- August 07, 2024
- Vendor
- Microsoft
- Product
- Jet Database Engine
- Description
- Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.
CVSS Scores
CVSS v2.0
9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploit Status
- Exploited in the Wild
- Yes (2008-03-25 16:00:00 UTC) Source
References
http://www.securitytracker.com/id?1019686
http://www.kb.cert.org/vuls/id/936529
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-028
https://exchange.xforce.ibmcloud.com/vulnerabilities/41380
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://marc.info/?l=bugtraq&m=121129490723574&w=2
http://www.microsoft.com/technet/security/advisory/950627.mspx
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CVE | 2008-03-25 16:00:00 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel