CVE-2016-0147

Severity
8.8HIGH
EPSS
26.4%
top 3.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 12
Latest updateMay 14

Description

Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

3
GHSA
GHSA-7r55-xf64-gwj6: Microsoft XML Core Services 32022-05-14
CVEList
CVE-2016-0147: Microsoft XML Core Services 32016-04-12
VulnCheck
Microsoft XMP Core Services Improper Input Validation2016
CVE-2016-0147 (HIGH CVSS 8.8) | Microsoft XML Core Services 3.0 all | cvebase.io