Information Disclosure Vulnerability in Microsoft XML Core Services
CVE-2014-0266
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 February 2014
Summary
The vulnerability exists within the XMLHTTP ActiveX controls in Microsoft XML Core Services, where improper enforcement of the Same Origin Policy allows remote attackers to gain access to sensitive data. By crafting a malicious web page that exploits this weakness, attackers can retrieve data from a different origin, potentially leading to unauthorized disclosure of information. This affects a broad range of Windows operating systems, making it crucial for users and administrators to apply the relevant security updates.
References
EPSS Score
37% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved