CVE-2017-0045HighCVSS 5.6

Windows DVD Maker XML External Entity Information Disclosure Vulnerability

Published
March 14, 2017
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in Windows when Windows DVD Maker fails to properly parse a specially crafted .msdvd file. An attacker who successfully exploited the vulnerability could obtain information to further compromise a target system. To exploit the vulnerability, an attacker would have to either log on locally to an affected system or convince a locally authenticated user to execute a specially crafted application. The security update addresses the vulnerability by correcting how Windows DVD Maker parses files.

🎯 Affected products4

  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Vista Service Pack 2
  • Windows Vista x64 Edition Service Pack 2

✅ Remediation

KB4012215 (Monthly Rollup) KB4012212 (Security Only) KB3205715 (Security Update)

🔗 References (7)