CVE-2017-0022
KEV PoC massInformation Disclosure in Microsoft XML Core Services (MSXML) on Windows
CISA: Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft XML Core Services (MSXML) on supported Windows client and server releases improperly handles objects in memory, allowing a remote attacker to test whether specific files exist on a victim's disk. The flaw is triggered when a user is lured to a crafted website (user interaction is required), typically via browser-delivered web content rather than through a network service. A successful attacker gains only information about file presence on disk, which is useful for reconnaissance in follow-on attacks but does not directly enable code execution. Essentially every Windows version of that era is affected, from Vista SP2 through Windows 10 1607 and Windows Server 2016, so the affected population is the broad Windows installed base at the time. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24) and public analysis documents its use by exploit kits, so in-the-wild exploitation is confirmed.
What to do: Apply Microsoft's security updates across all affected Windows releases as CISA's KEV required action specifies, prioritizing end-user workstations and multi-user systems where web browsing occurs. For legacy systems that no longer receive patches (Vista SP2, Server 2008), upgrade, restrict users from untrusted web content, or consider micro-patching; when auditing older images, verify the MSXML update is installed.
| microsoft XML Core Services (MSXML) | — |
| microsoft Windows Vista | SP2 |
| microsoft Windows 7 | SP1 |
| microsoft Windows 8.1 | all supported editions |
| microsoft Windows RT 8.1 | all supported editions |
| microsoft Windows 10 | Gold (1507), 1511, 1607 |
| microsoft Windows Server 2008 | SP2 |
| microsoft Windows Server 2008 R2 | SP1 |
| microsoft Windows Server 2012 | Gold |
| microsoft Windows Server 2012 R2 | all supported editions |
| microsoft Windows Server 2016 | all supported editions |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."
- Affected
- Microsoft XML Core Services
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- xml core services, windows 8.1, windows server 2008, windows server 2012
- Weakness
- CWE-119
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N