Information Disclosure Vulnerability in Microsoft XML Core Services
CVE-2015-2440

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 August 2015

Summary

Microsoft XML Core Services versions 3.0, 5.0, and 6.0 are susceptible to an information disclosure vulnerability. Attackers can exploit this weakness by crafting malicious websites that, when visited, may allow unauthorized access to sensitive information. This vulnerability circumvents the Address Space Layout Randomization (ASLR) protection mechanism, putting users at risk. It is crucial for users and administrators to implement the latest security updates from Microsoft to mitigate potential threats linked to this vulnerability.

References

EPSS Score

20% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.