Описание
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."
Ссылки
- ExploitThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
- ExploitThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
Windows DVD Maker XML External Entity Information Disclosure Vulnerability
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."
Уязвимость операционной системы Windows, позволяющая нарушителю получить информацию для компроментации целевой системы
EPSS
5.5 Medium
CVSS3
4.3 Medium
CVSS2