CVE-2017-0022
published 2017-03-17CVE-2017-0022: Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows…
PriorityP277medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-06-14
Exploited in the wild
EPSS
18.07%
96.9th percentile
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | xml_core_services | — | — |
| microsoft_corporation | xml_core_services | — | — |
| msrc | microsoft_xml_core_services_3.0 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP responses containing MSXML res:// protocol file-probing patterns used by CVE-2017-0022 exploit (AdGholas/Neutrino EK). Trend Micro DDI Rule 2358 covers this: 'CVE-2017-0022 - Microsoft XML Information Disclosure - HTTP (Response)'. ↗
- →TippingPoint MainlineDV filter 27047 targets the parseError information disclosure pattern over HTTP from Internet Explorer. ↗
- →TippingPoint MainlineDV filter 27061 targets ActiveX parseError.errorCode invocation over HTTP, a key indicator of CVE-2017-0022 exploitation. ↗
- →Exploit differentiates file existence by comparing XMLDOM parseError.errorCode values: 0x80070485 (file absent) vs 0x80004005 (file present); monitor JavaScript reading parseError.errorCode after LoadXML with res:// URIs. ↗
- →Exploit targets RT_VERSION (16), RT_MANIFEST (24), RT_ICON (3), and RT_MESSAGETABLE (11) resource types via res:// protocol to fingerprint installed security software and sandbox presence. ↗
- →Deep Security DPI rule 1008173 can be used to detect network-level exploitation of CVE-2017-0022. ↗
- ·The exploit was observed in the wild as early as July 2016 (AdGholas campaign) and September 2016 (Neutrino EK), well before the March 2017 patch; unpatched systems remain at risk. ↗
- ·The vulnerability is confirmed exploited in the wild per Microsoft MSRC; exploitation likelihood is rated 'More Likely' for both latest and older software releases. ↗
- ·After patching, IsCrossDomainDownload is always set to true regardless of file existence, making the error code 0x80004005 constant and eliminating the timing/error-code side-channel; detection rules relying on differential error codes will not fire on patched systems. ↗
- ·CVE-2017-0022 was used as a fingerprinting/evasion step (detecting security tools and sandboxes) rather than for direct code execution; it is typically chained with other exploits in malvertising campaigns. ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck6.5MEDIUM
cisa6.5MEDIUM
vendor_msrc4.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft XML Core Services Information Disclosure Vulnerability
cisa·2022-05-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CWE-200 Microsoft XML Core Services Information Disclosure Vulnerability
Vulnerability: Microsoft XML Core Services Information Disclosure Vulnerability
Affected: Microsoft XML Core Services
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0022
Remediation Due Date: 2022-06-14
Microsoft
Microsoft XML Core Services Information Disclosure Vulnerability
vendor_msrc·2017-03-14·CVSS 4.3
CVE-2017-0022 [MEDIUM] Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft XML Core Services Information Disclosure Vulnerability
Description: An information vulnerability exists when Microsoft XML Core Services (MSXML) improperly handles objects in memory. Successful exploitation of the vulnerability could allow the attacker to test for the presence of files on disk.
To exploit the vulnerability, an attacker could host a specially-crafted website that is designed to invoke MSXML through Internet Explorer. However, an attacker would have no way to force a user to visit such a website. Instead, an attacker would typically have to convince a user to either click a link in an email message or a link in an Instant Messenger request that would then take the user to the website.
The update addresses the vulnerability by changing the way MSXML handles objects
GHSA
GHSA-r6m8-274g-vhp5: Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8
ghsa_unreviewed·2022-05-17
CVE-2017-0022 [MEDIUM] CWE-119 GHSA-r6m8-274g-vhp5: Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability."
VulnCheck
Microsoft XML Core Services Information Disclosure Vulnerability
vulncheck·2017·CVSS 6.5
CVE-2017-0022 [MEDIUM] CWE-200 Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft XML Core Services Information Disclosure Vulnerability
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
Affected: Microsoft XML Core Services
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2017-Mar; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-06-14
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Exploits & Vulnerabilities
# CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro
2017/03/24
Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the same cam
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Exploits & Vulnerabilities
## CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro Mar 24, 2017 Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability ( CVE-2017-0022 ), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the same
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Exploits & Vulnerabilities
## CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro 2017/03/24 Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability ( CVE-2017-0022 ), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the same c
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Ausnutzung von Schwachstellen
## CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro Mar 24, 2017 Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability ( CVE-2017-0022 ), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the s
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Sfruttamento vulnerabilità
## CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro Mar 24, 2017 Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability ( CVE-2017-0022 ), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the same
Trendmicro
CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
blogs_trendmicro·2017-03-24·CVSS 6.5
CVE-2017-0022 [MEDIUM] CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Exploits y vulnerabilidades
## CVE-2017-0022 Exploited by AdGholas, Neutrino Patched
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability (CVE-2017-0022), which we reported to Microsoft in September 2016. This was used in the AdGholas campaign and later integrated into the Neutrino EK
By: Trend Micro Mar 24, 2017 Read time: ( words)
Save to Folio
Part of this month’s Patch Tuesday is an update for a zero-day information disclosure vulnerability ( CVE-2017-0022 ), which we privately reported to Microsoft in September 2016. This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the sam
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Exploits & Vulnerabilities
# March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro
2017/03/15
Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB). This vulnerability potentially allows cyber criminals to render affected system
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Ausnutzung von Schwachstellen
## March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro Mar 15, 2017 Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012 , which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB) . This vulnerability potentially allows cyber criminals to render affected
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Sfruttamento vulnerabilità
## March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro Mar 15, 2017 Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012 , which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB) . This vulnerability potentially allows cyber criminals to render affected sy
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Exploits y vulnerabilidades
## March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro Mar 15, 2017 Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012 , which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB) . This vulnerability potentially allows cyber criminals to render affected s
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Exploits & Vulnerabilities
## March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro 2017/03/15 Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012 , which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB) . This vulnerability potentially allows cyber criminals to render affected syst
Trendmicro
March 2017 Patch Tuesday: 18 Security Bulletins
blogs_trendmicro·2017-03-15·CVSS 7.8
CVE-2017-0016 [HIGH] March 2017 Patch Tuesday: 18 Security Bulletins
Exploits & Vulnerabilities
## March 2017 Patch Tuesday: 18 Security Bulletins
Patch Tuesday for March is hefty, with essentially two months’ worth of updates after Microsoft delayed its February patch release. Notable among the critical bulletins is MS17-012, which resolves several vulnerabilities including CVE-2017-0016.
By: Trend Micro Mar 15, 2017 Read time: ( words)
Save to Folio
Patch Tuesday for March is a hefty one, with essentially two months’ worth of updates after Microsoft quietly delayed its February patch release. Notable among the critical bulletins is MS17-012 , which resolves several vulnerabilities including CVE-2017-0016, a zero-day vulnerability involving Windows Server Message Block (SMB) . This vulnerability potentially allows cyber criminals to render affected sy
Zscaler
Zscaler found Multiple Security Vulnerabilities | 03-14-2017
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 03-14-2017
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.securityfocus.com/bid/96069http://www.securitytracker.com/id/1038014https://0patch.blogspot.com/2017/09/exploit-kit-rendezvous-and-cve-2017-0022.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0022http://www.securityfocus.com/bid/96069http://www.securitytracker.com/id/1038014https://0patch.blogspot.com/2017/09/exploit-kit-rendezvous-and-cve-2017-0022.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0022https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-0022
2017-03-17
Published
2022-05-24
Added to CISA KEV
Exploited in the wild