Vulnerability CVE-2008-1446

Rehman, Umar 12/31/2022 1 Reputation point
2021-03-18T17:05:09.343+00:00

We are running window server 2008 standard edition with SP2. Our security team has run a PCI Pen test on our web server and it came up with the report mentioned below.

Our sites are hosted on IIS 7.0 .

We have tried installing security patch KB953155 but it is only available to server with SP1 installed.

Is CVE-2008-1446 related to a site hosted on IIS 7.0 or this is something related to printing service running on the server ?

What are our options here?

PCI Pen Test Report

Description and Observation (xyz is a company name here)
A XYZ system was running Windows IIS Server version 7.0 which is affected by known vulnerabilities.
Business Impact
An attacker could potentially exploit the identified vulnerabilities to gain unauthorized access to the remote system, execute malicious code or cause a
DoS condition. This in turn could provide opportunity for a threat actor to gain internal access to resources, distribute malware or gain the ability to perform
website defacement. Code to exploit one of the security vulnerabilities affecting Windows IIS Server 7.0 is publicly available.
Affected URL
● our_site_hosted_on_iis.com
Affected CVE
● CVE-2008-1446
Recommendation(s)
XYZ should consider reviewing the security advisories associated with the application to determine the extent of which the server may
be vulnerable from a versioning and configuration perspective. Improve the current patch process to install the appropriate software upgrades as
described in the vendor’s advisories on a timely basis. Additionally, improve functional vulnerability scanning to identify and remediate these issues.


Internet Information Services
Windows Server Printing
Windows Server Printing
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Printing: Printer centralized deployment and management, scan and fax resources management, and document services
641 questions
Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,728 questions
{count} votes