CVE-2015-1646: Medium severity microsoft xml core services vulnerability
Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1646?
CVE-2015-1646 has a critical severity rating because it allows remote attackers to bypass security mechanisms.
How do I fix CVE-2015-1646?
To fix CVE-2015-1646, upgrade Microsoft XML Core Services 3.0 to the latest version or apply the recommended security updates.
What impact does CVE-2015-1646 have on my system?
CVE-2015-1646 can allow attackers to access sensitive information by circumventing the Same Origin Policy.
Is CVE-2015-1646 limited to certain operating systems?
CVE-2015-1646 specifically affects systems using Microsoft XML Core Services 3.0.
What should I do if I cannot update to fix CVE-2015-1646?
If updating is not possible, consider implementing additional access controls or disabling MSXML to mitigate the risk of CVE-2015-1646.