CVE-2015-6096Sensitive Information Exposure in Microsoft NET Framework

Severity
4.3MEDIUMNVD
EPSS
27.9%
top 3.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 11
Latest updateMay 14

Description

The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

NVDmicrosoft/net_framework8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-f7gf-x22g-qj66: The XML DTD parser in Microsoft2022-05-14
CVEList
CVE-2015-6096: The XML DTD parser in Microsoft2015-11-11
CVE-2015-6096 — Sensitive Information Exposure | cvebase