First published: Thu Jun 16 2011(Updated: )
The XML Editor in Microsoft InfoPath 2007 SP2 and 2010; SQL Server 2005 SP3 and SP4 and 2008 SP1, SP2, and R2; SQL Server Management Studio Express (SSMSE) 2005; and Visual Studio 2005 SP1, 2008 SP1, and 2010 does not properly handle external entities, which allows remote attackers to read arbitrary files via a crafted .disco (Web Service Discovery) file, aka "XML External Entities Resolution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SQL Server Management Studio | =2005 | |
Microsoft SQL Server | =2005-sp4 | |
Microsoft SQL Server | =2008-r2 | |
Microsoft SQL Server | =2008-sp2 | |
Microsoft SQL Server | =2008-sp2 | |
Microsoft Visual Studio | =2005-sp1 | |
Microsoft Office InfoPath | =2007-sp2 | |
Microsoft SQL Server | =2005-sp4 | |
Microsoft SQL Server Management Studio | =2005 | |
Microsoft SQL Server | =2005-sp4 | |
Microsoft Visual Studio | =2008-sp1 | |
Microsoft SQL Server | =2005-sp4 | |
Microsoft SQL Server | =2005-sp4 | |
Microsoft SQL Server | =2008-r2 | |
Microsoft Visual Studio | =2010 | |
Microsoft SQL Server | =2005-sp3 | |
Microsoft SQL Server | =2005-sp3 | |
Microsoft Office InfoPath | =2010 | |
Microsoft SQL Server | =2008-sp1 | |
Microsoft SQL Server | =2005-sp3 | |
Microsoft SQL Server | =2008-sp1 | |
Microsoft Office InfoPath | =2010 | |
Microsoft SQL Server | =2008-sp2 | |
Microsoft SQL Server | =2005-sp3 | |
Microsoft SQL Server | =2005-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1280 is considered a critical vulnerability due to its potential for remote code execution.
To fix CVE-2011-1280, you should apply the latest security updates from Microsoft for the affected software.
CVE-2011-1280 affects Microsoft InfoPath 2007 SP2, SQL Server versions 2005 and 2008, Visual Studio 2005, 2008, and 2010.
CVE-2011-1280 can be exploited by attackers to read arbitrary files on the server through crafted XML data.
CVE-2011-1280 was disclosed in April 2011 as part of Microsoft's regular security updates.