2009-4073 | Microsoft Internet Explorer information disclosure (BID-37117 / SBV-24301)
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
4.8 | $0-$5k | 0.25 |
A vulnerability was found in Microsoft Internet Explorer 8 (Web Browser). It has been classified as problematic. Affected is some unknown processing. The manipulation with an unknown input leads to a information disclosure vulnerability. CWE is classifying the issue as CWE-200. This is going to have an impact on confidentiality.
The issue has been introduced in 03/05/2008. The weakness was published 11/24/2009 by Inferno (Website). The advisory is available at theregister.co.uk. This vulnerability is traded as CVE-2009-4073 since 11/24/2009. The exploitability is told to be easy. It is possible to launch the attack remotely. The exploitation doesn’t require any form of authentication. Technical details are unknown but an exploit is available.
After before and not just, there has been an exploit disclosed. It is declared as proof-of-concept. The vulnerability was handled as a non-public zero-day exploit for at least 629 days. During that time the estimated underground price was around $25k-$100k.
Upgrading eliminates this vulnerability.
The vulnerability is also documented in the vulnerability database at Vulnerability Center (SBV-24301). Similar entry is available at 50914.
Type
Vendor
Name
VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 4.8
VulDB Base Score: 5.3
VulDB Temp Score: 4.8
VulDB Vector: 🔍
VulDB Reliability: 🔍
AV | AC | Au | C | I | A |
---|---|---|---|---|---|
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
Vector | Complexity | Authentication | Confidentiality | Integrity | Availability |
---|---|---|---|---|---|
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
VulDB Base Score: 🔍
VulDB Temp Score: 🔍
VulDB Reliability: 🔍
NVD Base Score: 🔍
Class: Information disclosure
CWE: CWE-200
ATT&CK: Unknown
Local: No
Remote: Yes
Availability: 🔍
Status: Proof-of-Concept
Price Prediction: 🔍
Current Price Estimation: 🔍
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
OpenVAS ID: 900897
OpenVAS Name: Microsoft Internet Explorer PDF Information Disclosure Vulnerability – Nov09
OpenVAS File: 🔍
OpenVAS Family: 🔍
Threat Intelligence
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍
0-Day Time: 🔍
Upgrade: theregister.co.uk
03/05/2008 🔍
11/23/2009 🔍
11/23/2009 🔍
11/24/2009 🔍
11/24/2009 🔍
11/24/2009 🔍
11/24/2009 🔍
11/25/2009 🔍
12/08/2009 🔍
03/18/2015 🔍
08/28/2021 🔍Vendor: https://www.microsoft.com/
Advisory: theregister.co.uk
Researcher: Inferno
Status: Not defined
CVE: CVE-2009-4073 (🔍)
OVAL: 🔍
Vulnerability Center: 24301 – Microsoft Internet Explorer 8 PDF Generation Vulnerability Allows Information Disclosure, Medium
SecurityFocus: 37117 – Microsoft Internet Explorer PDF Generation Information Disclosure Vulnerability
OSVDB: 60504 – Microsoft IE PDF Export Title Property File Path Disclosure
scip Labs: https://www.scip.ch/en/?labs.20161013
See also: 🔍
Created: 03/18/2015 15:15
Updated: 08/28/2021 05:27
Changes: (2) source_cve_assigned vulnerability_cvss2_nvd_basescore
Complete: 🔍
Comments
Enable the mail alert feature now!