vendor:
Microsoft Event Viewer
by:
John Page aka hyp3rlinx
5.5
CVSS
MEDIUM
XML External Entity
611
CWE
Product Name: Microsoft Event Viewer
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE: CVE-2019-0948
CPE: a:microsoft:event_viewer:1.0
Platforms Tested: Windows 7 SP1
2016
Microsoft Event Viewer XXE File Exfiltration
Windows Event Viewer user can import 'Custom View' files, these files contain XML, the parser processes External Entity potentially allowing attackers to gain remote file access to files on a victims system if user imports a corrupt XML file via remote share/USB (or other untrusted source).