MS15-084: Vulnerabilities in XML Core Services Could Allow Information Disclosure (3080129)
Medium Nessus Plugin ID 85335
SynopsisThe remote host is affected by multiple information disclosure vulnerabilities.
DescriptionThe remote Windows host contains a version of Microsoft XML Core Services (MSXML) that is affected by multiple information disclosure vulnerabilities :
- An information disclosure vulnerability exists in XML Core Services (MSXML) due to the use of Secure Sockets Layer (SSL) 2.0. A man-in-the-middle attacker can exploit this vulnerability by forcing an encrypted SSL 2.0 session and then decrypting the resulting network traffic. (CVE-2015-2434, CVE-2015-2471)
- An information disclosure vulnerability exists in XML Core Services (MSXML) due to exposing sensitive memory addresses. A remote attacker, using a specially crafted website, can exploit this to bypass ASLR and gain access to private data. (CVE-2015-2440)
SolutionMicrosoft has released a set of patches for Windows Vista, 2008, 7, 2008 R2, 8, 2012, 8.1, 2012 R2, RT, RT 8.1, Office 2007 SP3, and InfoPath 2007 SP3.