PT-2014-1687 · Microsoft · Xml Core Services+1

Christian Kulenkampff

·

Published

2014-06-10

·

Updated

2018-10-12

·

CVE-2014-1816

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft XML Core Services (aka MSXML) versions 3.0 through 6.0
Description The issue is related to the processing of XML content and allows attackers to gain access to confidential information. It does not properly restrict the information transmitted by Internet Explorer during a download action, enabling remote attackers to discover full pathnames on the client system and local usernames embedded in these pathnames via a crafted web site.
Recommendations For Microsoft XML Core Services (aka MSXML) versions 3.0 through 6.0, consider restricting the information transmitted by Internet Explorer during download actions to minimize the risk of exploitation. As a temporary workaround, consider disabling the use of MSXML for handling XML content until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-00635
CVE-2014-1816

Affected Products

Internet Explorer
Xml Core Services