VulnerabilityModified
CVE-2015-1646
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."
MEDIUM 4.3EPSS 16.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 16.86% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/xml core services
- Source
- secure@microsoft.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.