vendor:
Microsoft Baseline Security Analyzer
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: Microsoft Baseline Security Analyzer
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE:
CPE: cpe:2.3
Platforms Tested:
2018
Microsoft Baseline Security Analyzer 2.3 – XML External Entity Injection
Microsoft Baseline Security Analyzer allows local files to be exfiltrated to a remote attacker controlled server if a user opens a specially crafted ".mbsa" file.
Mitigation:
Ensure that the Microsoft Baseline Security Analyzer is updated to the latest version.