Lucene search

K
kasperskyKaspersky LabKLA10013
HistoryJun 10, 2014 - 12:00 a.m.

KLA10013 OSI vulnerability in multiple Microsoft XML Core Services

2014-06-1000:00:00
Kaspersky Lab
threats.kaspersky.com
78

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.006

Percentile

78.3%

By exploiting this vulnerability malicious users can obtain sensitive information. This vulnerability can be exploited from the network at a point related to MSXML via a specially designed website. It is caused by a missing property information restriction.

Original advisories

MS Bulletin

CVE-2014-1816

Related products

Microsoft-Windows

Microsoft-Windows-Server

CVE list

CVE-2014-1816 warning

KB list

2966631

2957482

2966061

2939576

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • PE

Privilege escalation. Exploitation of vulnerabilities with this impact can lead to performing by abuser actions, which are normally disallowed for current role.

Affected Products

  • Windows Server 2003 SP2 x86, x64, for ItaniumWindows Vista SP2 x86, x64Windows Server 2008 SP2 x86, x64, for ItaniumWindows 7 SP1 x86, x64Windows Server 2008 R2Β SP1 x64, for ItaniumWindows 8 x86, x64 Windows 8.1 x86, x64Windows Server 2012, 2012 R2Windows RT &Β Windows RT 8.1

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.006

Percentile

78.3%