peter bassill · operator
$ cve CVE-2008-5229 JSON

CVE-2008-5229 EXPLOIT

6.9
MEDIUM · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.

Scoring

CVSS6.9 (MEDIUM, v2.0)
VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
EPSS2.59% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2008-11-25
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftwindows vista

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD