CVE-2008-1456 is an array index vulnerability in the Event System of multiple Microsoft Windows operating systems, including Windows 2000, XP, Server 2003, Vista, and Server 2008. This flaw allows remote authenticated users to execute arbitrary code by crafting an event subscription request that manipulates an array of function pointers. With a CVSS score of 9.0, this vulnerability is critical, requiring only network access and authentication for a complete compromise of confidentiality, integrity, and availability. Despite its high severity and EPSS score, there is no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2008CPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:2008:*:*:*:*:*:*:* | ||
vistaCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:vista:*:gold:*:*:*:*:* | ||
xpCPE matchmatch criteria | cpe:2.3:o:microsoft:windows-nt:xp:sp3:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:sp1:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.