Executive brief
Microsoft XML Core Services (MSXML) improperly handles objects in memory, leading to an information disclosure vulnerability. An attacker can exploit this by hosting a crafted website to test for the existence of specific files on a user's disk.
Affected products
- Microsoft XML Core Services 3.0
- Microsoft Windows 10 Gold, 1511, 1607
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows Server 2016
- Microsoft Windows Vista SP2
Timeline
- 2017-09-01: exploited: Exploit kit activity reported by 0patch.
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-05-24: disclosed