CVE-2008-5229
Last modified
CVE-2008-5229 is a vulnerability of currently unknown severity. Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Windows Vista | All versions | Sp1 |
| Microsoft | Windows Vista | gold | — |
References
- http://secunia.com/advisories/32791Vendor Advisory
- http://secunia.com/advisories/32791Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-5229?
How severe is CVE-2008-5229?
How do I fix CVE-2008-5229?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-5223SQL injection vulnerability in index.php in Airvae Commerce …
- CVE-2008-5224Cross-site scripting (XSS) vulnerability in Kent Web Mart 1.…
- CVE-2008-5225Multiple cross-site scripting (XSS) vulnerabilities in Xerox…
- CVE-2008-5226SQL injection vulnerability in the MambAds (com_mambads) com…
- CVE-2008-5227Unspecified vulnerability in PHPCow allows remote attackers …
- CVE-2008-5228Cross-site scripting (XSS) vulnerability in IBM Workplace Co…
- CVE-2008-5230The Temporal Key Integrity Protocol (TKIP) implementation in…
- CVE-2008-5231Stack-based buffer overflow in the ExecuteRequest method in …
- CVE-2008-5232Buffer overflow in the CallHTMLHelp method in the Microsoft …
- CVE-2008-5233xine-lib 1.1.12, and other versions before 1.1.15, does not …
- CVE-2008-5234Multiple heap-based buffer overflows in xine-lib 1.1.12, and…
- CVE-2008-5235Heap-based buffer overflow in the demux_real_send_chunk func…
Are you affected by CVE-2008-5229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
