CVE-2017-0022 PUBLISHED KEV CVSS 4.300000190734863 MEDIUM

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."

EPSS 44.11% · 97.5th percentile

Risk Scores

CVSS v2.0
4.300000190734863
EPSS Score
44.11%
97.5th percentile

Affected Products

VendorProductVersions
microsoftxml_core_services3.0, 3.0
microsoftwindows_server_2012r2, r2
microsoftwindows_server_2008r2, r2
microsoftwindows_8.1
Microsoft CorporationXML Core ServicesXML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2

Timeline

References

Open in Interactive Console →