Lucene search

K
kasperskyKaspersky LabKLA10558
HistoryApr 14, 2015 - 12:00 a.m.

KLA10558 Obtain sensitive information vulnerability in MSXML

2015-04-1400:00:00
Kaspersky Lab
threats.kaspersky.com
21

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.665

Percentile

98.0%

An unspecified vulnerability was found in Microsoft XML Core Services. By exploiting this vulnerability malicious users can bypass security restrictions or obtain sensitive information. This vulnerability can be exploited remotely via a specially designed DTD.

Original advisories

MS15-039

CVE-2015-1646

Related products

Microsoft-XML-Core-Services

CVE list

CVE-2015-1646 warning

KB list

3046482

Solution

Update to the latest version

Impacts

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

Affected Products

  • Microsoft XML Core Services version 3.0

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.5

Confidence

Low

EPSS

0.665

Percentile

98.0%