vendor:
Windows DVD Maker
by:
John Page AKA hyp3rlinx
5,5
CVSS
MEDIUM
XML External Entity Injection
611
CWE
Product Name: Windows DVD Maker
Affected Version From: 6.1.7
Affected Version To: 6.1.7
Patch Exists: YES
Related CWE: CVE-2017-0045, MS17-020
CPE: a:microsoft:windows_dvd_maker:6.1.7
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2008 R2 Service Pack 1, Windows Server 2008 R2 Datacenter, Windows Server 2008 R2 Enterprise, Windows Server 2008 R2 Standard, Windows Web Server 2008 R2, Windows Server 2008 R2 Foundation, Windows 7 Service Pack 1, Windows 7 Ultimate, Windows 7 Enterprise, Windows 7 Professional, Windows 7 Home Premium, Windows 7 Home Basic, Windows 7 Starter, Windows Server 2008 Service Pack 2, Windows Server 2008 Foundation, Windows Server 2008 Standard, Windows Server 2008 for Itanium-Based Systems, Windows Web Server 2008, Windows Server 2008 Enterprise, Windows Server 2008 Datacenter, Windows Vista Service Pack 2, Windows Vista Home Basic, Windows Vista Home Premium, Windows Vista Business, Windows Vista Ultimate, Windows Vista Enterprise, Windows Vista Starter
2017
Microsoft DVD Maker XML External Entity File Disclosure
Windows DVD Maker Project '.msdvd' files are prone to XML External Entity attacks allowing remote attackers to gain access to files from a victims computer using a specially crafted malicious .msdvd file, resulting in remote information / file disclosures.
Mitigation:
Microsoft has released a security update to address this vulnerability.