CVE-2015-2556
The InfoPath Forms Services component in Microsoft SharePoint Server 2007 SP3 and 2010 SP2 misparses DTDs, which allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.6%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The InfoPath Forms Services component in Microsoft SharePoint Server 2007 SP3 and 2010 SP2 misparses DTDs, which allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "Microsoft SharePoint Information Disclosure Vulnerability."
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 15.62% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- microsoft/sharepoint server
- Source
- secure@microsoft.com
References
- http://www.securitytracker.com/id/1033804Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-110
- http://www.securitytracker.com/id/1033804Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2015/ms15-110
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.