Skip to content
COOEY

EXPOSURES › CVE-2017-0022

CVE-2017-0022

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-24 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-0022 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatched

An information disclosure flaw in Microsoft XML Core Services allowed attackers to test for files on disk via a crafted website.

This vulnerability in Microsoft XML Core Services (MSXML) allowed attackers to test for files on disk by exploiting improper memory handling. For DIB organizations, this means attackers could potentially map out sensitive file structures, aiding further attacks like ransomware or data exfiltration. Organizations must ensure MSXML is patched and monitor for exploitation attempts.

Shame score — While not a zero-day or RCE, this is a known, actively exploited vulnerability (KEV) that attackers used to gather intelligence, representing a moderate embarrassment due to its widespread exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized