Security readout for executives and security teams
This is a legacy Windows XChat issue: if Internet Explorer opens a crafted ircs:// link, XChat can receive an injected --command argument and run commands. The sources identify XChat 2.8.7b and earlier. Exposure depends on installed XChat, Windows protocol handling, and IE use. Most current enterprise exposure is likely limited unless legacy Windows endpoints still have XChat 2.8.7b or earlier installed and associated with ircs:// links. Internet Explorer use or compatibility paths increase relevance. Asset inventory should determine real exposure. Prioritize as a legacy exposure cleanup item. It is serious where present because it can lead to command execution, but broad urgency depends on whether affected XChat, Windows protocol association, and Internet Explorer conditions still exist. Mitigation focus: Remove XChat from Windows systems where it is no longer required.; Upgrade or replace XChat based on vendor or maintainer guidance.; Disable or reassess ircs:// protocol-handler associations on Windows endpoints..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2008-2841 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- xchat-ircs-command-execution(43065)CVE reference · vdb-entry, x_refsource_XF
- 5795CVE reference · exploit, x_refsource_EXPLOIT-DB
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
