vendor:
Enhanced Mitigation Experience Toolkit (EMET)
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
XML External Entity Injection
611
CWE
Product Name: Enhanced Mitigation Experience Toolkit (EMET)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:emet
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
Microsoft Windows EMET XML Injection
EMETs XML parser does not account for external entity declarations in '.config' files. This allows outbound network connections and users local files to be exfiltrated to remote attacker controlled server. Conditions are a user must be tricked into importing a specially crafted XML file.
Mitigation:
Ensure that all XML files are validated and sanitized before being imported into EMET.