#VU8318 XXE in Windows Server and Windows - CVE-2017-8710
Published: September 12, 2017 / Updated: September 12, 2017
Windows Server
Windows
Microsoft
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
An information disclosure vulnerability exists in the Windows System Information Console when it improperly parses XML input containing a reference to an external entity. A remote attacker can create a specially crafted XML file, trick the victim into opening it and gain access to potentially sensitive information.