vendor:
Visual Studio 2008 Express IDE
by:
John Page (aka hyp3rlinx)
8.8
CVSS
HIGH
XML External Entity Injection 0Day
N/A
CWE
Product Name: Visual Studio 2008 Express IDE
Affected Version From: 2008
Affected Version To: 2008
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Visual Studio 2008 – XML External Entity Injection
Visual Studio 2008 IDE suffers from XML External Entity injection. Attackers can leverage many file types, some being MASM related files like .asm or .lst. By opening any one of the following file types listed below, it can allow remote attackers to steal files from the victims computer, sending them to the remote attackers server. Double click any of the following extensions and it will trigger the XXE vulnerability. Note, upon installation of the IDE the following file types get associated with Visual Studio 2008 and are ALL vulnerable and will trigger the XXE exploit.
Mitigation:
Upgrade to the latest version of Visual Studio.