CVE-2008-3009
Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."
Published:Dec 10, 2008
Last Modified:Apr 23, 2026
EPS:Dec 10, 2008
EPSS Score:0.52277
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Windows 2000
Microsoft
Windows 2000
Vendor
Microsoft
Product
Windows Media Format Runtime
Microsoft
Windows Media Format Runtime
Vendor
Microsoft
Product
Windows Media Player
Microsoft
Windows Media Player
Vendor
Microsoft
Product
Windows Media Services
Microsoft
Windows Media Services
Vendor
Microsoft
Product
Windows Server 2003
Microsoft
Windows Server 2003
Vendor
Microsoft
Product
Windows Server 2008
Microsoft
Windows Server 2008
Vendor
Microsoft
Product
Windows Vista
Microsoft
Windows Vista
Vendor
Microsoft
Product
Windows Xp
Microsoft
Windows Xp
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
