CVE-2017-0022CISA KEV
Microsoft XML Core Services Information Disclosure Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
- Product
- XML Core Services
- Added to KEV
- 24 May 2022
- Federal remediation due
- 14 Jun 2022
- Known ransomware use
- Not reported