CVE-2017-0022HighCVSS 4.3

Microsoft XML Core Services Information Disclosure Vulnerability

Published
March 14, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information vulnerability exists when Microsoft XML Core Services (MSXML) improperly handles objects in memory. Successful exploitation of the vulnerability could allow the attacker to test for the presence of files on disk. To exploit the vulnerability, an attacker could host a specially-crafted website that is designed to invoke MSXML through Internet Explorer. However, an attacker would have no way to force a user to visit such a website. Instead, an attacker would typically have to convince a user to either click a link in an email message or a link in an Instant Messenger request that would then take the user to the website. The update addresses the vulnerability by changing the way MSXML handles objects in memory.

🎯 Affected products34

  • Microsoft XML Core Services 3.0 on Windows 10 Version 1511 for 32-bit Systems
  • Microsoft XML Core Services 3.0 on Windows 10 Version 1511 for x64-based Systems
  • Microsoft XML Core Services 3.0 on Windows 10 Version 1607 for 32-bit Systems
  • Microsoft XML Core Services 3.0 on Windows 10 Version 1607 for x64-based Systems
  • Microsoft XML Core Services 3.0 on Windows 10 for 32-bit Systems
  • Microsoft XML Core Services 3.0 on Windows 10 for x64-based Systems
  • Microsoft XML Core Services 3.0 on Windows 7 for 32-bit Systems Service Pack 1
  • Microsoft XML Core Services 3.0 on Windows 7 for x64-based Systems Service Pack 1
  • Microsoft XML Core Services 3.0 on Windows 8.1 for 32-bit systems
  • Microsoft XML Core Services 3.0 on Windows 8.1 for x64-based systems
  • Microsoft XML Core Services 3.0 on Windows RT 8.1
  • Microsoft XML Core Services 3.0 on Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
  • Microsoft XML Core Services 3.0 on Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Microsoft XML Core Services 3.0 on Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Server 2008 for 32-bit Systems Service Pack 2
  • Microsoft XML Core Services 3.0 on Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Server 2008 for Itanium-Based Systems Service Pack 2
  • Microsoft XML Core Services 3.0 on Windows Server 2008 for x64-based Systems Service Pack 2
  • Microsoft XML Core Services 3.0 on Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Server 2012
  • Microsoft XML Core Services 3.0 on Windows Server 2012 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Server 2012 R2
  • Microsoft XML Core Services 3.0 on Windows Server 2012 R2 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Server 2016
  • Microsoft XML Core Services 3.0 on Windows Server 2016 (Server Core installation)
  • Microsoft XML Core Services 3.0 on Windows Vista Service Pack 2
  • Microsoft XML Core Services 3.0 on Windows Vista x64 Edition Service Pack 2
  • Windows 8.1 for 32-bit systems
  • Windows 8.1 for x64-based systems
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • +4 more not shown

✅ Remediation

KB4012216 (Monthly Rollup) KB4012213 (Security Only) KB4012215 (Monthly Rollup) KB4012212 (Security Only) KB4012217 (Monthly Rollup) KB4012214 (Security Only) KB3216916 (Security Update) KB4012606 (Security Update) KB4013198 (Security Update) KB4013429 (Security Update)

🔗 References (21)