vendor:
Authorization Manager
by:
John Page aka hyp3rlinx
8,8
CVSS
HIGH
XML External Entity
611
CWE
Product Name: Authorization Manager
Affected Version From: Microsoft Authorization Manager v6.1.7601
Affected Version To: Microsoft Authorization Manager v6.1.7601
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:authorization_manager:6.1.7601
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2020
Microsoft Authorization Manager XXE File Exfiltration
The parser processes XML External Entity nodes allowing external connections to be made to remote malicious DTD documents that can potentially allow access to files on users system to be exfiltrated to a remote server.
Mitigation:
Microsoft has not released a patch for this vulnerability. To mitigate this vulnerability, users should not open any untrusted XML files with Authorization Manager.