CVE Feed

    Dashboard / CVE / CVE-2008-3068

    CVE-2008-3068

    Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

    Published:Jul 7, 2008
    Last Modified:Apr 23, 2026
    EPS:Jul 7, 2008
    EPSS Score:0.12634
    CVSS Score:7.5

    Affected Products

    Vendor
    Microsoft
    Product
    Access
    Vendor
    Microsoft
    Product
    Excel
    Vendor
    Microsoft
    Product
    Frontpage
    Vendor
    Microsoft
    Product
    Groove
    Vendor
    Microsoft
    Product
    Infopath
    Vendor
    Microsoft
    Product
    Office
    Vendor
    Microsoft
    Product
    Office Communicator
    Vendor
    Microsoft
    Product
    Onenote
    Vendor
    Microsoft
    Product
    Outlook
    Vendor
    Microsoft
    Product
    Powerpoint
    Vendor
    Microsoft
    Product
    Project Professional
    Vendor
    Microsoft
    Product
    Project Standard
    Vendor
    Microsoft
    Product
    Publisher
    Vendor
    Microsoft
    Product
    Sharepoint Designer
    Vendor
    Microsoft
    Product
    Visio Professional
    Vendor
    Microsoft
    Product
    Visio Standard
    Vendor
    Microsoft
    Product
    Windows Live Mail

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High