CVE-2008-1092

High PUBLISHED

Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted...

Microsoft · Jet Database Engine

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.3 High

At a Glance

Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.

CVE Published
Mar 25, 2008
Exploitation Reported
Mar 25, 2008
CVSS
9.3 High
EPSS
Remote Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • MS08-028 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • SSRT080071 marc.info · Vendor Advisory http://marc.info/?l=bugtraq&m=121129490723574&w=2
  • 950627 microsoft.com · Vendor Advisory http://www.microsoft.com/technet/security/advisory/950627.mspx
  • VU#936529 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/936529
  • 1019686 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1019686
Show 1 more reference

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.