cbcvebase.
CVE-2015-6096
published 2015-11-11

CVE-2015-6096: The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an…

PriorityP344medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
61.02%
99.1th percentile
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability class is XML External Entity (XXE) injection via external entity declaration combined with an entity reference in the XML DTD parser of .NET Framework — monitor for outbound file-read requests triggered by XML parsing in .NET applications
  • Exploitation is remotely achievable with low attack complexity and no authentication — treat any externally reachable .NET service that parses XML (including OPC UA endpoints) as an exposed attack surface for XXE-based file disclosure
  • Successful exploitation allows reading of arbitrary files on the file system — look for anomalous file-read activity or unexpected outbound DNS/HTTP connections from .NET processes handling XML input
  • ·Only .NET Framework versions 4.5, 4.0, and 3.5 are affected in the OPC UA context; .NET 4.5.2 and later are recommended as the patched baseline
  • ·No known public exploits specifically target this vulnerability at time of advisory publication
  • ·Affected OPC UA product scope is limited to Unified Automation .NET based OPC UA Client/Server SDK Bundle versions V3.0.7 and prior using .NET 4.5, 4.0, and 3.5 Framework versions only
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.