{"api_version":"1","generated_at":"2026-07-23T08:44:13+00:00","cve":"CVE-2008-5229","urls":{"html":"https://cve.report/CVE-2008-5229","api":"https://cve.report/api/cve/CVE-2008-5229.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5229","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5229"},"summary":{"title":"CVE-2008-5229","description":"Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a \"route add\" command.  NOTE: this issue might not cross privilege boundaries.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-11-25 23:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.9","severity":"","vector":"AV:L/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/498650/100/0/threaded","name":"http://www.securityfocus.com/archive/1/498650/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32791","name":"http://secunia.com/advisories/32791","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Windows Vista \"CreateIpForwardEntry2()\" Memory Corruption Vulnerability - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1021245","name":"http://securitytracker.com/id?1021245","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityTracker.com Archives - Windows Vista Buffer Overflow in CreateIpForwardEntry2() May Let Local Users Gain Elevated Privileges","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/498471/100/0/threaded","name":"http://www.securityfocus.com/archive/1/498471/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/x-c","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4646","name":"http://securityreason.com/securityalert/4646","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"SecurityReason - Microsoft VISTA TCP/IP stack buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46742","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32357","name":"http://www.securityfocus.com/bid/32357","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Microsoft Windows Vista 'iphlpapi.dll' Local Kernel Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5229","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5229","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5229","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5229","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"gold","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:49:12.237Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20081125 Re: Microsoft VISTA TCP/IP stack buffer overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/498650/100/0/threaded"},{"name":"win-vista-iphlpapi-bo(46742)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46742"},{"name":"20081119 Microsoft VISTA TCP/IP stack buffer overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/498471/100/0/threaded"},{"name":"32791","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32791"},{"name":"1021245","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1021245"},{"name":"4646","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4646"},{"name":"32357","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32357"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-11-19T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a \"route add\" command.  NOTE: this issue might not cross privilege boundaries."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20081125 Re: Microsoft VISTA TCP/IP stack buffer overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/498650/100/0/threaded"},{"name":"win-vista-iphlpapi-bo(46742)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46742"},{"name":"20081119 Microsoft VISTA TCP/IP stack buffer overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/498471/100/0/threaded"},{"name":"32791","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32791"},{"name":"1021245","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1021245"},{"name":"4646","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4646"},{"name":"32357","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32357"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5229","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a \"route add\" command.  NOTE: this issue might not cross privilege boundaries."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20081125 Re: Microsoft VISTA TCP/IP stack buffer overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/498650/100/0/threaded"},{"name":"win-vista-iphlpapi-bo(46742)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/46742"},{"name":"20081119 Microsoft VISTA TCP/IP stack buffer overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/498471/100/0/threaded"},{"name":"32791","refsource":"SECUNIA","url":"http://secunia.com/advisories/32791"},{"name":"1021245","refsource":"SECTRACK","url":"http://securitytracker.com/id?1021245"},{"name":"4646","refsource":"SREASON","url":"http://securityreason.com/securityalert/4646"},{"name":"32357","refsource":"BID","url":"http://www.securityfocus.com/bid/32357"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5229","datePublished":"2008-11-25T23:00:00.000Z","dateReserved":"2008-11-25T00:00:00.000Z","dateUpdated":"2024-08-07T10:49:12.237Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-11-25 23:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","baseScore":6.9,"accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:*","matchCriteriaId":"C162FFF0-1E8F-4DCF-A08F-6C6E324ED878"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:gold:*:*:*:*:*:*:*","matchCriteriaId":"1D12423F-FCCD-4F4C-9037-7607C1F1F99E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5229","Ordinal":"1","Title":"CVE-2008-5229","CVE":"CVE-2008-5229","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5229","Ordinal":"1","NoteData":"Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a \"route add\" command.  NOTE: this issue might not cross privilege boundaries.","Type":"Description","Title":"CVE-2008-5229"},{"CveYear":"2008","CveId":"5229","Ordinal":"2","NoteData":"2008-11-25","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5229","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}