CVE-2017-0045HighCVSS 5.6
Windows DVD Maker XML External Entity Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists in Windows when Windows DVD Maker fails to properly parse a specially crafted .msdvd file. An attacker who successfully exploited the vulnerability could obtain information to further compromise a target system. To exploit the vulnerability, an attacker would have to either log on locally to an affected system or convince a locally authenticated user to execute a specially crafted application. The security update addresses the vulnerability by correcting how Windows DVD Maker parses files.
🎯 Affected products4
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
✅ Remediation
KB4012215 (Monthly Rollup) KB4012212 (Security Only) KB3205715 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0045
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012215
- referencehttps://support.microsoft.com/en-us/help/4012215
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012212
- referencehttps://support.microsoft.com/en-us/help/4012212
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB3205715
- referencehttps://support.microsoft.com/en-us/kb/3205715