CVE-2011-1713
Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft msxml.dll, as used in Internet Explorer 8 on Windows 7, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function. NOTE: this might overlap CVE-2011-1202.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 11.20% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/internet explorer
- Source
- cve@mitre.org
References
- http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66835
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12693
- http://scarybeastsecurity.blogspot.com/2011/03/multi-browser-heap-address-leak-in-xslt.htmlExploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66835
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12693
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.