SB2017071129 - Information disclosure in Windows Performance Monitor



SB2017071129 - Information disclosure in Windows Performance Monitor

Published: July 11, 2017

Security Bulletin ID SB2017071129
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) XXE attack (CVE-ID: CVE-2017-0170)

The vulnerability allows a remote attacker to conduct XXE attack.

The weakness exists due to improper parsing of XML input containing a reference to an external entity. A remote attacker can send manipulated XML data, convince the victim to create a Data Collector Set and import the file that may allow the attacker to read arbitrary file.

Successful exploitation of the vulnerability may result in information disclosure.

Remediation

Install update from vendor's website.