CVE-2014-1816: Medium severity Microsoft XML Core Services vulnerability
Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1816?
CVE-2014-1816 is considered a moderate severity vulnerability.
How do I fix CVE-2014-1816?
To fix CVE-2014-1816, you should update Microsoft XML Core Services to a patched version.
What software is affected by CVE-2014-1816?
CVE-2014-1816 affects Microsoft XML Core Services version 3.0 and 6.0.
What can an attacker do with CVE-2014-1816?
An attacker exploiting CVE-2014-1816 can potentially discover full pathnames and local usernames from the client system.
Is there a workaround for CVE-2014-1816?
There are no specific workarounds for CVE-2014-1816; applying the security update is recommended.