CVE-2016-3255High

.NET Framework Information Disclosure Vulnerability

Published
July 12, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists when .NET Framework improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity declaration. To exploit the vulnerability, an attacker could create specially crafted XML data and induce an application to parse and validate the XML data. For example, an attacker could create an XML file and upload it to a web-based application. The update addresses the vulnerability by modifying the way that the XML External Entity (XXE) parser parses XML input.

🎯 Affected products54

  • Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for 32-bit Systems Service Pack 2
  • Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
  • Microsoft .NET Framework 2.0 Service Pack 2 on Windows Server 2008 for x64-based Systems Service Pack 2
  • Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista Service Pack 2
  • Microsoft .NET Framework 2.0 Service Pack 2 on Windows Vista x64 Edition Service Pack 2
  • Microsoft .NET Framework 3.5 on Windows 10 Version 1511 for 32-bit Systems
  • Microsoft .NET Framework 3.5 on Windows 10 Version 1511 for x64-based Systems
  • Microsoft .NET Framework 3.5 on Windows 10 for 32-bit Systems
  • Microsoft .NET Framework 3.5 on Windows 10 for x64-based Systems
  • Microsoft .NET Framework 3.5 on Windows 8.1 for 32-bit systems
  • Microsoft .NET Framework 3.5 on Windows 8.1 for x64-based systems
  • Microsoft .NET Framework 3.5 on Windows Server 2012
  • Microsoft .NET Framework 3.5 on Windows Server 2012 (Server Core installation)
  • Microsoft .NET Framework 3.5 on Windows Server 2012 R2
  • Microsoft .NET Framework 3.5 on Windows Server 2012 R2 (Server Core installation)
  • Microsoft .NET Framework 3.5.1 on Windows 7 for 32-bit Systems Service Pack 1
  • Microsoft .NET Framework 3.5.1 on Windows 7 for x64-based Systems Service Pack 1
  • Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
  • Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Microsoft .NET Framework 3.5.1 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Microsoft .NET Framework 4.5.2 on Windows 7 for 32-bit Systems Service Pack 1
  • Microsoft .NET Framework 4.5.2 on Windows 7 for x64-based Systems Service Pack 1
  • Microsoft .NET Framework 4.5.2 on Windows 8.1 for 32-bit systems
  • Microsoft .NET Framework 4.5.2 on Windows 8.1 for x64-based systems
  • Microsoft .NET Framework 4.5.2 on Windows RT 8.1
  • Microsoft .NET Framework 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Microsoft .NET Framework 4.5.2 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Microsoft .NET Framework 4.5.2 on Windows Server 2008 for 32-bit Systems Service Pack 2
  • Microsoft .NET Framework 4.5.2 on Windows Server 2008 for x64-based Systems Service Pack 2
  • Microsoft .NET Framework 4.5.2 on Windows Server 2012
  • +24 more not shown

✅ Remediation

KB3164025 (Security Update) KB3163251 (Security Update) KB3163244 (Security Update) KB3163247 (Security Update) KB3163912 (Security Update) KB3172985 (Security Update) KB3163246 (Security Update) KB3163245 (Security Update) KB3163291 (Security Update) KB3163250 (Security Update) KB3164024 (Security Update) KB3164023 (Security Update)

🔗 References (15)