CVE-2015-6096
published 2015-11-11CVE-2015-6096: The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an…
PriorityP344medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
61.02%
99.1th percentile
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability class is XML External Entity (XXE) injection via external entity declaration combined with an entity reference in the XML DTD parser of .NET Framework — monitor for outbound file-read requests triggered by XML parsing in .NET applications ↗
- →Exploitation is remotely achievable with low attack complexity and no authentication — treat any externally reachable .NET service that parses XML (including OPC UA endpoints) as an exposed attack surface for XXE-based file disclosure ↗
- →Successful exploitation allows reading of arbitrary files on the file system — look for anomalous file-read activity or unexpected outbound DNS/HTTP connections from .NET processes handling XML input ↗
- ·Only .NET Framework versions 4.5, 4.0, and 3.5 are affected in the OPC UA context; .NET 4.5.2 and later are recommended as the patched baseline ↗
- ·No known public exploits specifically target this vulnerability at time of advisory publication ↗
- ·Affected OPC UA product scope is limited to Unified Automation .NET based OPC UA Client/Server SDK Bundle versions V3.0.7 and prior using .NET 4.5, 4.0, and 3.5 Framework versions only ↗
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f7gf-x22g-qj66: The XML DTD parser in Microsoft
ghsa_unreviewed·2022-05-14
CVE-2015-6096 [MEDIUM] CWE-200 GHSA-f7gf-x22g-qj66: The XML DTD parser in Microsoft
The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
CISA ICS
OPC UA Products Built with the .NET Framework 4.5, 4.0, and 3.5
cisa_ics·2021-05-13·CVSS 7.5
[HIGH] OPC UA Products Built with the .NET Framework 4.5, 4.0, and 3.5
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
OPC UA Products Built with the .NET Framework 4.5, 4.0, and 3.5
Last RevisedMay 13, 2021
Alert CodeICSA-21-133-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Unified Automation GmbH
- Equipment: .NET applications
- Vulnerability: Exposure of Sensitive Information to an Unauthorized Actor
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an unauthenticated attacker to read any file on the file system.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following OPC UA products are
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
## Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
## Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively
Talos
Microsoft Patch Tuesday - November 2015
blogs_talos·2015-11-10·CVSS 9.3
[CRITICAL] Microsoft Patch Tuesday - November 2015
Microsoft's Patch Tuesday has arrived. Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release contains 12 bulletins addressing 53 vulnerabilities. Four bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, Windows Journal, and Windows. The remaining eight bulletins are rated important and address vulnerabilities in .NET, IPsec, Kerberos, Lync/Skype for Business, NDIS, Office, SChannel, and Winsock.
### Bulletins Rated Critical Microsoft bulletins MS15-112 through MS15-115 are rated as critical in this month's release.
MS15-112 and MS15-113 are this month's Internet Explorer and Edge security bulletin respectively. In total, 25 vulnerabilities are addresse
Zscaler
Zscaler detects IE & MS Office Vulnerabilities | 11-10-2015
blogs_zscaler·CVSS 9.3
[CRITICAL] Zscaler detects IE & MS Office Vulnerabilities | 11-10-2015
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2015-11-11
Published