CVE-2008-1454
Status: ModifiedHigh (9.4)—
Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:C/A:C
- Base score: 9.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 34%
- Percentile among all scored CVEs: 98
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (4)
CWEs
- NVD-CWE-noinfo
References
- http://secunia.com/advisories/30925
- http://www.securityfocus.com/bid/30132
- http://www.securitytracker.com/id?1020437
- http://www.us-cert.gov/cas/techalerts/TA08-190A.html
- http://www.vupen.com/english/advisories/2008/2019/references
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-037
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5380
- http://secunia.com/advisories/30925
- http://www.securityfocus.com/bid/30132
- http://www.securitytracker.com/id?1020437
- http://www.us-cert.gov/cas/techalerts/TA08-190A.html
- http://www.vupen.com/english/advisories/2008/2019/references
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-037
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5380
Raw JSON (NVD)
Show
{
"id": "CVE-2008-1454",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 9.4,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": true,
"impactScore": 9.2,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-07-08T23:41:00.000",
"references": [
{
"url": "http://secunia.com/advisories/30925",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/30132",
"tags": [
"Patch"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id?1020437",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2019/references",
"tags": [
"Vendor Advisory"
],
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-037",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5380",
"source": "secure@microsoft.com"
},
{
"url": "http://secunia.com/advisories/30925",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30132",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1020437",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA08-190A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2019/references",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-037",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5380",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting \"records from a response that is outside the remote server's authority,\" aka \"DNS Cache Poisoning Vulnerability,\" a different vulnerability than CVE-2008-1447."
},
{
"lang": "es",
"value": "La vulnerabilidad no especificada en Microsoft DNS en Windows 2000 SP4, Server 2003 SP1 y SP2, y Server 2008 permite a los atacantes remotos dirigir ataques de intoxicación por caché por medio de vectores desconocidos relacionados con la aceptación de \"records from a response that is outside the remote server's authority\", también se conoce como \"DNS Cache Poisoning Vulnerability\", esta una vulnerabilidad diferente a CVE-2008-1447."
}
],
"lastModified": "2026-06-16T22:51:46.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA778424-6F70-4AB6-ADD5-5D4664DFE463"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp1:itanium:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCE2197B-7C58-4693-B9BB-0B31EABB6B66"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp1:x64:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8D91FC0B-92FA-4182-9B87-A462850BD510"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D3B5E4F-56A6-4696-BBB4-19DF3613D020"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:*:*:x32:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9CFB1A97-8042-4497-A45D-C014B5E240AB"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:*:*:x64:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7F9C7616-658D-409D-8B53-AC00DC55602A"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@microsoft.com"
}