vendor:
GDFMaker
by:
John Page (aka hyp3rlinx)
7.5
CVSS
HIGH
XML External Entity
611
CWE
Product Name: GDFMaker
Affected Version From: v6.3.9600.16384
Affected Version To: v6.3.9600.16384
Patch Exists: NO
Related CWE:
CPE: a:microsoft:gdfmaker:6.3.9600.16384
Platforms Tested: Windows
2017
MS-WINDOWS-GAME-DEFINITION-FILE-MAKER-v6.3.9600-XML-EXTERNAL-ENTITY
If a user loads an attacker supplied "GDFMakerProject" file type into GDF Maker using Ctrl+O or file menu, local files can be exfiltrated to remote attacker controlled server, as gdfmaker.exe is vulnerable to XML External Entity Expansion attacks.