CVE-2008-1086 describes a critical remote code execution vulnerability in the HxTocCtrl ActiveX control (hxvz.dll), affecting Microsoft Internet Explorer 5.01 SP4 and 6 SP1, as well as various Windows operating systems including XP SP2, Server 2003 SP1/SP2, Vista SP1, and Server 2008. This flaw allows attackers to execute arbitrary code by supplying malformed arguments, leading to memory corruption. With a CVSS score of 9.3 (Critical) and a FAUCET Risk Score of 98/100, this vulnerability presents a significant risk due to its network-based attack vector, medium complexity, and complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score indicating a higher likelihood of exploitation compared to most CVEs, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.01CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2008:*:itanium:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2008:*:x32:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2008:*:x64:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.