EXPOSURES › CVE-2017-0022
CVE-2017-0022
HIGH ⌖ ON CISA KEV · EXPLOITEDAn information disclosure flaw in Microsoft XML Core Services allowed attackers to test for files on disk via a crafted website.
This vulnerability in Microsoft XML Core Services (MSXML) allowed attackers to test for files on disk by exploiting improper memory handling. For DIB organizations, this means attackers could potentially map out sensitive file structures, aiding further attacks like ransomware or data exfiltration. Organizations must ensure MSXML is patched and monitor for exploitation attempts.
Shame score — While not a zero-day or RCE, this is a known, actively exploited vulnerability (KEV) that attackers used to gather intelligence, representing a moderate embarrassment due to its widespread exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |