CVE-2008-4301 describes a potential vulnerability in Microsoft Internet Information Services (IIS) where a specific ActiveX control in iisext.dll might allow remote attackers to set a password using the SetPassword method. Despite a CVSS score of 10.0 indicating critical severity with full confidentiality, integrity, and availability impact, the vulnerability's existence is highly questionable due to an unreliable researcher and inability to reproduce the issue by a reliable third party. There is no known exploit code available in Metasploit, Nuclei, or ExploitDB, and it has received no community discussion or media coverage, suggesting it is not actively exploited or considered a credible threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:internet_information_services:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.