CVE-2017-8557
published 2017-07-11CVE-2017-8557: Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows…
PriorityP425medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
1.54%
72.1th percentile
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability improperly parses XML input containing a reference to an external entity, aka "Windows System Information Console Information Disclosure Vulnerability".
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows System Information Console Information Disclosure Vulnerability
vendor_msrc·2017-07-11·CVSS 5.5
CVE-2017-8557 [MEDIUM] Windows System Information Console Information Disclosure Vulnerability
Windows System Information Console Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in the Microsoft Common Console Document (.msc) when it improperly parses XML input containing a reference to an external entity. An attacker who successfully exploited this vulnerability could read arbitrary files via an XML external entity (XXE) declaration.
To exploit the vulnerability, an attacker could create a file containing specially crafted XML content and convince an authenticated user to open the file.
The update addresses the vulnerability by modifying the way that the Microsoft Common Console Document (.msc) parses XML input.
Microsoft Windows: Microsoft Windows
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;
GHSA
GHSA-xv2g-h4p5-m8rq: Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
ghsa_unreviewed·2022-05-14
CVE-2017-8557 [MEDIUM] CWE-611 GHSA-xv2g-h4p5-m8rq: Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure vulnerability improperly parses XML input containing a reference to an external entity, aka "Windows System Information Console Information Disclosure Vulnerability".
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/99387http://www.securityfocus.com/bid/99398http://www.securitytracker.com/id/1038855https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8557http://www.securityfocus.com/bid/99387http://www.securityfocus.com/bid/99398http://www.securitytracker.com/id/1038855https://portal.msrc.microsoft.com/en-us/security-guidance/advisory/CVE-2017-8557
2017-07-11
Published