Information Disclosure in Microsoft XML Core Services by Remote Attackers
CVE-2015-2471

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
15 August 2015

Summary

Microsoft XML Core Services versions 3.0, 5.0, and 6.0 have a vulnerability that supports SSL 2.0, creating a pathway for remote attackers to compromise cryptographic protections. By leveraging network sniffing techniques, these attackers can execute decryption attacks to gain unauthorized access to sensitive information.

References

EPSS Score

39% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.