vendor:
FxCop
by:
Debashis Pal
8.8
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: FxCop
Affected Version From: Microsoft Windows FxCop v10-12
Affected Version To: Microsoft Windows FxCop v10-12
Patch Exists: YES
Related CWE: N/A
CPE: a:microsoft:fxcop
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 and Windows 10
2018
Microsoft Windows FxCop 10/12 – XML External Entity Injection
FxCop is vulnerable to XML injection attacks allowing local file exfiltration and or NTLM hash theft. Tested in Windows 7 and Windows 10 download SDK it works in both. If you have the the particular SDK in question it is probably there but needs to be installed as it was for me.
Mitigation:
Upgrade to FxCop 14.0 or later versions