CVE-2016-3255
published 2016-07-13CVE-2016-3255: Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity…
PriorityP355high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
24.66%
97.6th percentile
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| msrc | microsoft_net_framework_2.0_service_pack_2 | — | — |
| msrc | microsoft_net_framework_3.5 | — | — |
| msrc | microsoft_net_framework_3.5.1 | — | — |
| msrc | microsoft_net_framework_4.5.2 | — | — |
| msrc | microsoft_net_framework_4.6 | — | — |
| msrc | microsoft_net_framework_4.6.1 | — | — |
| msrc | microsoft_net_framework_4.6_4.6.1 | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjhp-6pqp-7242: Microsoft
ghsa_unreviewed·2022-05-14
CVE-2016-3255 [HIGH] CWE-200 GHSA-gjhp-6pqp-7242: Microsoft
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
Microsoft
.NET Framework Information Disclosure Vulnerability
vendor_msrc·2016-07-12·CVSS 7.5
CVE-2016-3255 [HIGH] .NET Framework Information Disclosure Vulnerability
.NET Framework Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists when .NET Framework improperly parses XML input containing a reference to an external entity.
An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity declaration.
To exploit the vulnerability, an attacker could create specially crafted XML data and induce an application to parse and validate the XML data. For example, an attacker could create an XML file and upload it to a web-based application.
The update addresses the vulnerability by modifying the way that the XML External Entity (XXE) parser parses XML input.
.NET Framework: .NET Framework
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer and Edge security bulletins respectively
Talos
Microsoft Patch Tuesday - July 2016
blogs_talos·2016-07-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday - July 2016
## Microsoft Patch Tuesday - July 2016
This post was authored by William Largent
Today, Microsoft has released their monthly set of security bulletins designed to address security vulnerabilities within their products. This month’s release is has 11 bulletins addressing 49 vulnerabilities. 6 of these bulletins are rated critical and address vulnerabilities in Edge, Internet Explorer, JScript/VBScript, Print Spooler, Office and Adobe Flash Player. The remaining bulletins are rated important and address vulnerabilities in Windows Kernel, Office, Kernel-Mode Drivers, .NET Framework, and Secure Boot.
## Bulletins Rated Critical Microsoft bulletins MS16-084 through MS16-088, and MS16-093 are rated as critical in this month's release.
MS16-084 and MS16-085 are this month's Internet Explorer
http://www.securityfocus.com/bid/91601http://www.securitytracker.com/id/1036291https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-091http://www.securityfocus.com/bid/91601http://www.securitytracker.com/id/1036291https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-091
2016-07-13
Published