4.3
CVSSv2

CVE-2017-0045

Published: 17/03/2017 Updated: 16/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows malicious users to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows 7

microsoft windows server 2008

microsoft windows server 2008 r2

microsoft windows vista

Exploits

[+] Credits: John Page AKA hyp3rlinx [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/MICROSOFT-DVD-MAKER-XML-EXTERNAL-ENTITY-FILE-DISCLOSUREtxt [+] ISR: ApparitionSec Vendor: ================= wwwmicrosoftcom Product: ================= Windows DVD Maker v617 Windows DVD Maker is a feature ...
Windows DVD Maker version 617 suffers from an XML external entity injection vulnerability ...