Vulnerability Name:

CVE-2008-4816 (CCN-46336)

Assigned:2008-11-04
Published:2008-11-04
Updated:2018-10-30
Summary:Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2008-4816

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:026

Source: CCN
Type: SA32872
SUSE Update for Multiple Packages

Source: SECUNIA
Type: UNKNOWN
32872

Source: CCN
Type: SECTRACK ID: 1021140
Adobe Acrobat Multiple Flaws Let Remote Users Execute Arbitrary Code

Source: CCN
Type: NORTEL BULLETIN ID: 2008009218, Rev 1
Nortel Response to Adobe Vulnerability Identifier APSB08-19

Source: CCN
Type: Adobe Product Security Bulletin APSB08-19
Security Update available for Adobe Reader 8 and Acrobat 8

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.adobe.com/support/security/bulletins/apsb08-19.html

Source: CCN
Type: OSVDB ID: 50243
Adobe Reader Download Manager Unspecified Remote Internet Security Options Manipulation

Source: CCN
Type: BID-32103
NOS Microsystems getPlus Download Manager Unauthorized Access Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021140

Source: CERT
Type: US Government Resource
TA08-309A

Source: VUPEN
Type: UNKNOWN
ADV-2008-3001

Source: XF
Type: UNKNOWN
adobe-reader-dlmgr-security-bypass(46336)

Source: SUSE
Type: SUSE-SR:2008:026
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*
  • AND
  • cpe:/a:adobe:acrobat:8.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:8.1.1:unknown:3d:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:8.1.1:unknown:professional:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:8.1.1:unknown:standard:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat:*:unknown:3d:*:*:*:*:* (Version <= 8.1.2)
  • OR cpe:/a:adobe:acrobat:*:unknown:professional:*:*:*:*:* (Version <= 8.1.2)
  • OR cpe:/a:adobe:acrobat:*:unknown:standard:*:*:*:*:* (Version <= 8.1.2)
  • OR cpe:/a:adobe:acrobat_reader:*:*:*:*:*:*:*:* (Version <= 8.0)
  • AND
  • cpe:/a:adobe:download_manager:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:adobe:acrobat_reader:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:8.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:8.1:*:*:*:*:*:*:*
  • OR cpe:/a:adobe:acrobat_reader:8.1.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20084816
    V
    CVE-2008-4816
    2015-11-16
    BACK
    microsoft windows *
    adobe acrobat 8.1.1
    adobe acrobat 8.1.1 unknown
    adobe acrobat 8.1.1 unknown
    adobe acrobat 8.1.1 unknown
    adobe acrobat * unknown
    adobe acrobat * unknown
    adobe acrobat * unknown
    adobe acrobat reader *
    adobe download manager *
    adobe acrobat reader 8.0
    adobe acrobat reader 8.1.2
    adobe acrobat reader 8.1
    adobe acrobat reader 8.1.1