ZeroHour

CVE-2017-0022

KEV PoC mass

Information Disclosure in Microsoft XML Core Services (MSXML) on Windows

CISA: Microsoft XML Core Services Information Disclosure Vulnerability

CVSS 3.1
6.5 medium
EPSS
18%p97
Published
()
KEV added
AI analysis

Microsoft XML Core Services (MSXML) on supported Windows client and server releases improperly handles objects in memory, allowing a remote attacker to test whether specific files exist on a victim's disk. The flaw is triggered when a user is lured to a crafted website (user interaction is required), typically via browser-delivered web content rather than through a network service. A successful attacker gains only information about file presence on disk, which is useful for reconnaissance in follow-on attacks but does not directly enable code execution. Essentially every Windows version of that era is affected, from Vista SP2 through Windows 10 1607 and Windows Server 2016, so the affected population is the broad Windows installed base at the time. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24) and public analysis documents its use by exploit kits, so in-the-wild exploitation is confirmed.

What to do: Apply Microsoft's security updates across all affected Windows releases as CISA's KEV required action specifies, prioritizing end-user workstations and multi-user systems where web browsing occurs. For legacy systems that no longer receive patches (Vista SP2, Server 2008), upgrade, restrict users from untrusted web content, or consider micro-patching; when auditing older images, verify the MSXML update is installed.

Affected
microsoft XML Core Services (MSXML)
microsoft Windows VistaSP2
microsoft Windows 7SP1
microsoft Windows 8.1all supported editions
microsoft Windows RT 8.1all supported editions
microsoft Windows 10Gold (1507), 1511, 1607
microsoft Windows Server 2008SP2
microsoft Windows Server 2008 R2SP1
microsoft Windows Server 2012Gold
microsoft Windows Server 2012 R2all supported editions
microsoft Windows Server 2016all supported editions
Estimated exposure
masshundreds of millions of Windows devices (MSXML ships with every affected Windows release, Vista through Windows 10 1607) — MSXML is a built-in Windows component, so the vulnerable set spans effectively the entire Windows installed base of that era (hundreds of millions of client PCs and millions of servers), though actual exploitation requires a user to visit…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."

CISA Known Exploited Vulnerability
Affected
Microsoft XML Core Services
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
xml core services, windows 8.1, windows server 2008, windows server 2012
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news