CVE-2014-1816

Description

Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka MSXML Entity URI Vulnerability.

Risk Information

Base Score
4.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
10.855

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows Server 2003 (KB2939576)Windows
Security Update for Windows Vista (KB2939576)Windows
Security Update for Windows Server 2008 (KB2939576)Windows
Security Update for Windows 7 (KB2939576)Windows
Security Update for Windows 8 (KB2939576)Windows
Security Update for Windows 8.1 (KB2939576)Windows
Security Update for Windows Server 2003 x64 Edition (KB2939576)Windows
Security Update for Windows Vista for x64-based Systems (KB2939576)Windows
Security Update for Windows Server 2008 x64 Edition (KB2939576)Windows
Security Update for Windows 7 for x64-based Systems (KB2939576)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2939576)Windows
Security Update for Windows 8 for x64-based Systems (KB2939576)Windows
Security Update for Windows Server 2012 (KB2939576)Windows
Security Update for Windows 8.1 for x64-based Systems (KB2939576)Windows
Security Update for Windows Server 2012 R2 (KB2939576)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2957482)Windows
Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2957482)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-15666Security Update for Windows Server 2003 (KB2939576)
PATCH-15667Security Update for Windows Vista (KB2939576)
PATCH-15668Security Update for Windows Server 2008 (KB2939576)
PATCH-15669Security Update for Windows 7 (KB2939576)
PATCH-15670Security Update for Windows 8 (KB2939576)
PATCH-15671Security Update for Windows 8.1 (KB2939576)
PATCH-15672Security Update for Windows Server 2003 x64 Edition (KB2939576)
PATCH-15673Security Update for Windows Vista for x64-based Systems (KB2939576)
PATCH-15674Security Update for Windows Server 2008 x64 Edition (KB2939576)
PATCH-15675Security Update for Windows 7 for x64-based Systems (KB2939576)
PATCH-15676Security Update for Windows Server 2008 R2 x64 Edition (KB2939576)
PATCH-15677Security Update for Windows 8 for x64-based Systems (KB2939576)
PATCH-15678Security Update for Windows Server 2012 (KB2939576)
PATCH-15679Security Update for Windows 8.1 for x64-based Systems (KB2939576)
PATCH-15680Security Update for Windows Server 2012 R2 (KB2939576)
PATCH-15681Security Update for Microsoft XML Core Services 6.0 Service Pack 2 (KB2957482)
PATCH-15682Security Update for Microsoft XML Core Services 6.0 Service Pack 2 for x64-based Systems (KB2957482)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234