CVE-2016-3255Sensitive Information Exposure in Microsoft NET Framework

Severity
7.5HIGHNVD
EPSS
29.5%
top 3.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 13
Latest updateMay 14

Description

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDmicrosoft/net_framework6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-gjhp-6pqp-7242: Microsoft2022-05-14
CVEList
CVE-2016-3255: Microsoft2016-07-13

📋Vendor Advisories

1
Microsoft
.NET Framework Information Disclosure Vulnerability2016-07-12
CVE-2016-3255 — Sensitive Information Exposure | cvebase