Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-07-07 16:41
Updated : 2018-10-11 13:45
NVD link : CVE-2008-3068
Mitre link : CVE-2008-3068
JSON object : View
CWE
Products Affected
microsoft
- powerpoint
- publisher
- project_standard
- sharepoint_designer
- office_communicator
- visio_standard
- visio_professional
- access
- frontpage
- windows_live_mail
- onenote
- excel
- groove
- project_professional
- office
- infopath
- outlook