Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-2547

Опубликовано: 04 июн. 2008
Источник: nvd
CVSS2: 9.3
EPSS Средний

Описание

Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components such as ActiveX controls, and might additionally require a separate vulnerability in the control.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:microsoft:windows_installer:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_installer:3.1.4000.1823:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_installer:4.5.6001.22159:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.29781
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components such as ActiveX controls, and might additionally require a separate vulnerability in the control.

EPSS

Процентиль: 96%
0.29781
Средний

9.3 Critical

CVSS2

Дефекты

CWE-119