CVE-2008-1457

The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted event subscription request.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows-nt:2008:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:vista:*:gold:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_2003_server:*:sp2:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*

History

No history.

Information

Published : 2008-08-13 12:42

Updated : 2024-02-04 17:33


NVD link : CVE-2008-1457

Mitre link : CVE-2008-1457

CVE.ORG link : CVE-2008-1457


JSON object : View

Products Affected

microsoft

  • windows_2003_server
  • windows_xp
  • windows_2000
  • windows_vista
  • windows-nt
CWE
CWE-20

Improper Input Validation