CyberSec.Space Logo
Back to CVE Browser

CVE-2008-3010

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.0030%
EPSS Percentile17.58th
PublishedDec 10, 2008
Last ModifiedApr 23, 2026

Vulnerability Description

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by sending an authentication request, aka "ISATAP Vulnerability."

Affected Platforms (CPE)

πŸ“¦
Microsoft

Windows Media Player

= 6.4

References & Advisories

Related Vulnerabilities