vendor:
Windows System Information
by:
John Page aka hyp3rlinx
7,5
CVSS
HIGH
XML External Entity
611
CWE
Product Name: Windows System Information
Affected Version From: Windows 7 SP1
Affected Version To: Windows 7 SP1
Patch Exists: NO
Related CWE: N/A
CPE: o:microsoft:windows_7::sp1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1
2017
Microsoft Windows MSINFO32.exe XML External Entity
Microsoft Windows MSINFO32.exe is vulnerable to XML External Entity attack which can potentially allow remote attackers to gain access to and exfiltrate files from the victims computer if they open a malicious ".nfo" file via remote share / USB etc.
Mitigation:
Disable MSINFO32.exe or restrict access to it.