CVE-2013-7331
בינונית 6.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Microsoft Internet Explorer Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local pathnames, UNC share pathnames, intranet hostnames, and intranet IP addresses by examining error codes, as demonstrated by a res:// URL, and exploited in the wild in February 2014.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L - EPSS — סבירות ניצול
- 58% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-209
מוצרים מושפעים
microsoft: internet explorer; microsoft: windows server 2003; microsoft: windows server 2008; microsoft: windows vista; microsoft: windows 7; microsoft: windows 8; microsoft: windows rt; microsoft: windows server 2012; microsoft: windows 8.1; microsoft: windows rt 8.1
קישורים
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-… PatchVendor Advisory
- https://soroush.secproject.com/blog/2013/04/microsoft-xmldom-in-ie-can-divulge… Exploit
- https://soroush.secproject.com/blog/2013/04/microsoft-xmldom-in-ie-can-divulge… Exploit
- http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-… Third Party Advisory
- http://www.kb.cert.org/vuls/id/539289 Third Party AdvisoryUS Government Resource
- http://www.securitytracker.com/id/1030818 Third Party AdvisoryVDB Entry
- http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-… Third Party Advisory
- http://www.kb.cert.org/vuls/id/539289 Third Party AdvisoryUS Government Resource
- http://www.securitytracker.com/id/1030818 Third Party AdvisoryVDB Entry