Microsoft XML Core Services Security Feature Bypass Vulnerability
Last Update Date:
15 Apr 2015 15:00
Release Date:
15 Apr 2015
3707
Views
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A same-origin policy security feature bypass vulnerability exists in Microsoft XML Core Services (MSXML) whereby cross-domain data access could be possible in a document type declaration (DTD) scenario. An attacker who successfully exploited this vulnerability could access sensitive user information, such as username or password and files on the hard drive.
Impact
- Security Restriction Bypass
System / Technologies affected
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS15-039
Vulnerability Identifier
Source
Related Link
Share with