MEDIUM · 4.3

CVE-2008-4033

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensiti...

Vulnerability Description

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MicrosoftXml Core Services4.0
MicrosoftWindows 2000All versions
MicrosoftWindows 2003 ServerAll versions
MicrosoftWindows 7All versions
MicrosoftWindows Server 2008All versions
MicrosoftWindows VistaAll versions
MicrosoftWindows XpAll versions
MicrosoftExpression WebAll versions
MicrosoftGroove2007
MicrosoftOffice2003
MicrosoftOffice Compatibility PackAll versions
MicrosoftOffice Word Viewer2003
MicrosoftSharepoint Server2007

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-4033?

CVE-2008-4033 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensiti...

How severe is CVE-2008-4033?

CVE-2008-4033 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-4033?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Xml Core Services, Microsoft Windows 2000, Microsoft Windows 2003 Server, Microsoft Windows 7, Microsoft Windows Server 2008.