Vulnerability Name: | CVE-2017-8710 (CCN-131143) | ||||||||||||
Assigned: | 2017-09-12 | ||||||||||||
Published: | 2017-09-12 | ||||||||||||
Updated: | 2019-10-03 | ||||||||||||
Summary: | The Microsoft Common Console Document (.msc) in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1 allows an attacker to read arbitrary files via an XML external entity (XXE) declaration, due to the way that the Microsoft Common Console Document (.msc) parses XML input containing a reference to an external entity, aka "Windows Information Disclosure Vulnerability". | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.1 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-611 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-8710 Source: BID Type: Third Party Advisory, VDB Entry 100793 Source: CCN Type: BID-100793 Microsoft Windows CVE-2017-8710 Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1039325 Source: XF Type: UNKNOWN ms-windows-cve20178710-info-disc(131143) Source: CCN Type: Microsoft Security TechCenter - September 2017 Windows Information Disclosure Vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-8710 Source: MISC Type: Exploit, Third Party Advisory https://www.vulnerability-lab.com/get_content.php?id=2094 Source: MISC Type: Exploit, Third Party Advisory https://www.youtube.com/watch?v=bIFot3a-58I | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |