CVE-2008-2246

Description

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended access restrictions.

Risk Information

Base Score
8.2
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
EPSS Score
Exploitation Probability
53.579

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Vista (KB953733) x86 based systemsWindows
Security Update for Windows Vista (KB953733) x86 based systems for SP1Windows
Security Update for Windows Server 2008 (KB953733)Windows
Security Update for Windows Server 2008 x64 Edition (KB953733)Windows
Security Update for Windows Vista for x64-based Systems (KB953733)Windows
Security Update for Windows Vista for x64-based Systems (KB953733) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-6202Security Update for Windows Server 2008 (KB953733)
PATCH-6203Security Update for Windows Server 2008 x64 Edition (KB953733)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234