CVE-2008-3068

N/A Unknown
Published: July 07, 2008 Modified: April 23, 2026
View on NVD

Description

Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://securityreason.com/securityalert/3978
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/493947/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/494101/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/28548
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1019736
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1019737
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1019738
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.cynops.de/advisories/AKLINK-SA-2008-002.txt
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.cynops.de/advisories/AKLINK-SA-2008-003.txt
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.cynops.de/advisories/AKLINK-SA-2008-004.txt
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.cynops.de/techzone/http_over_x509.html
Source: af854a3a-2127-422b-91ae-364da2661108

28 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
Exploitation Status
Not in CISA KEV

Affected Vendors

microsoft