vendor:
Windows Media Center
by:
John Page aka hyp3rlinx
7,5
CVSS
HIGH
XML External Entity
611
CWE
Product Name: Windows Media Center
Affected Version From: 6.1.7600
Affected Version To: 6.1.7600
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:windows_media_center:6.1.7600
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1
2016
Microsoft Windows Media Center XXE File Disclosure
Windows Media Center 'ehshell.exe' is vulnerable to XML External Entity attack allowing remote access to ANY files on a victims computer, if they open an XXE laden '.mcl' file via a remote share / USB or from an malicious 'windowsmediacenterweb' web link.
Mitigation:
Upgrade to latest version of Windows Media Center.