Oval Definition:oval:org.mitre.oval:def:8509
Revision Date:2014-08-18Version:44
Title:Blended Threat Remote Code Execution Vulnerability
Description:Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-2540
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):Microsoft Internet Explorer
Definition Synopsis
  • IE7/XP x86/x64
  • XP x86/x64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.16000
  • AND Mshtml.dll version is less than 7.0.6000.16825
  • OR IE7/XP x86/x64
  • XP x86/x64
  • Microsoft Windows XP (32-bit) is installed
  • OR Microsoft Windows XP x64 is installed
  • AND Microsoft Internet Explorer 7 is installed
  • AND Mshtml.dll version is greater than 7.0.6000.20000
  • AND Mshtml.dll version is less than 7.0.6000.21015
  • OR Windows 2000
  • Microsoft Windows 2000 is installed
  • AND The version of Secur32.dll is less than 5.0.2195.7244
  • OR Windows XP (32-bit)
  • Microsoft Windows XP (32-bit) is installed
  • AND The version of Kernel32.dll is less than 5.1.2600.3541
  • OR Windows XP (32-bit)
  • Microsoft Windows XP (32-bit) is installed
  • AND The version of Kernel32.dll is less than 5.1.2600.5781
  • OR XP x64, Server 2003 x86/x64/ia64
  • XP x64, Server 2003 x86/x64/ia64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND The version of Kernel32.dll is less than 5.2.3790.3311
  • OR XP x64, Server 2003 x86/x64/ia64
  • XP x64, Server 2003 x86/x64/ia64
  • Microsoft Windows XP x64 is installed
  • OR Microsoft Windows Server 2003 (x64) is installed
  • OR Microsoft Windows Server 2003 (32-bit) is installed
  • OR Microsoft Windows Server 2003 (ia64) Gold is installed
  • AND The version of Kernel32.dll is less than 5.2.3790.4480
  • OR Vista x86/x64
  • Vista x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND the version of Kernel32.dll is greater than or equal 6.0.6000.16000
  • AND The version of Kernel32.dll is less than 6.0.6000.16820
  • OR Vista x86/x64
  • Vista x86/x64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND the version of Kernel32.dll is greater than or equal 6.0.6000.20000
  • AND The version of Kernel32.dll is less than 6.0.6000.21010
  • OR Vista x86/x64, Server 2008 x86/x64/ia64
  • Vista x86/x64, Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND the version of Kernel32.dll is greater than or equal 6.0.6001.18000
  • AND The version of Kernel32.dll is less than 6.0.6001.18215
  • OR Vista x86/x64, Server 2008 x86/x64/ia64
  • Vista x86/x64, Server 2008 x86/x64/ia64
  • Microsoft Windows Vista (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND the version of Kernel32.dll is greater than or equal 6.0.6001.22000
  • AND The version of Kernel32.dll is less than 6.0.6001.22376
  • BACK