CVE-2014-0266

Description

The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to bypass the Same Origin Policy via a web page that is visited in Internet Explorer, aka MSXML Information Disclosure Vulnerability.

Risk Information

Base Score
4.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
31.859

Associated Vulnerability

VulnerabilityOS Platform
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows XP (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2003 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Vista (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2008 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 7 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 8 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 8.1 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows XP x64 Edition (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2003 x64 Edition (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Vista for x64-based Systems (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2008 x64 Edition (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 7 for x64-based Systems (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2008 R2 x64 Edition (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 8 for x64-based Systems (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2012 (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows 8.1 for x64-based Systems (KB2916036)Windows
ms14-005: vulnerability in microsoft xml core services could allow information disclosure: february 11, 2014 for Windows Server 2012 R2 (KB2916036)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-14987Security Update for Windows Server 2003 (KB2916036)
PATCH-14988Security Update for Windows Vista (KB2916036)
PATCH-14989Security Update for Windows Server 2008 (KB2916036)
PATCH-14990Security Update for Windows 7 (KB2916036)
PATCH-14991Security Update for Windows 8 (KB2916036)
PATCH-14992Security Update for Windows 8.1 (KB2916036)
PATCH-14993Security Update for Windows XP x64 Edition (KB2916036)
PATCH-14994Security Update for Windows Server 2003 x64 Edition (KB2916036)
PATCH-14995Security Update for Windows Vista for x64-based Systems (KB2916036)
PATCH-14996Security Update for Windows Server 2008 x64 Edition (KB2916036)
PATCH-14997Security Update for Windows 7 for x64-based Systems (KB2916036)
PATCH-14998Security Update for Windows Server 2008 R2 x64 Edition (KB2916036)
PATCH-14999Security Update for Windows 8 for x64-based Systems (KB2916036)
PATCH-15000Security Update for Windows Server 2012 (KB2916036)
PATCH-15001Security Update for Windows 8.1 for x64-based Systems (KB2916036)
PATCH-15002Security Update for Windows Server 2012 R2 (KB2916036)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234