Cross-Domain Vulnerability in Microsoft XML Core Services Affects Multiple Products
CVE-2008-4033
Currently unrated
What is CVE-2008-4033?
This vulnerability exists in Microsoft XML Core Services versions 3.0 through 6.0, as utilized across various Microsoft products including Expression Web, Office applications, and Internet Explorer. It allows remote attackers to leverage HTTP request header fields—specifically the Transfer-Encoding field—to gain unauthorized access to sensitive information from another domain and potentially manipulate the session state. This breach could expose users to further attacks by compromising the integrity of their sessions across different domains.