Information Disclosure Vulnerability in Microsoft XML Core Services
CVE-2014-0266

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 February 2014

Summary

The vulnerability exists within the XMLHTTP ActiveX controls in Microsoft XML Core Services, where improper enforcement of the Same Origin Policy allows remote attackers to gain access to sensitive data. By crafting a malicious web page that exploits this weakness, attackers can retrieve data from a different origin, potentially leading to unauthorized disclosure of information. This affects a broad range of Windows operating systems, making it crucial for users and administrators to apply the relevant security updates.

References

EPSS Score

37% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.