CVE-2017-0022
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."
- Affected products
- Msxml, Windows, Windows 10, Windows 7, Windows 8.1, Windows Rt 8.1, Windows Server 2008, Windows Server 2012
- Microsoft Xml Core Services
- = 3.0
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 18.1% (97th percentile)
- Weakness
- CWE-119
- NVD status
- Analyzed
- Published
- 2017-03-17
CVE-2017-0022 at NVD
No indexed exploits for CVE-2017-0022 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-0022 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.