CVE-2008-3466
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
Published:Oct 15, 2008
Last Modified:Apr 23, 2026
EPS:Oct 15, 2008
EPSS Score:0.8472
CVSS Score:10
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Host Integration Server 2000
Microsoft
Host Integration Server 2000
Vendor
Microsoft
Product
Host Integration Server 2004
Microsoft
Host Integration Server 2004
Vendor
Microsoft
Product
Host Integration Server 2006
Microsoft
Host Integration Server 2006
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
