CVE-2014-1816
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 14.36% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/xml core services
- Source
- secure@microsoft.com
References
- http://blogs.technet.com/b/srd/archive/2014/06/10/assessing-risk-for-the-june-2014-security-updates.aspxVendor Advisory
- http://secunia.com/advisories/58538Permissions Required
- http://www.securityfocus.com/bid/67895Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-033
- http://blogs.technet.com/b/srd/archive/2014/06/10/assessing-risk-for-the-june-2014-security-updates.aspxVendor Advisory
- http://secunia.com/advisories/58538Permissions Required
- http://www.securityfocus.com/bid/67895Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-033
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.