CVE-2016-3255: Infoleak
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka ".NET Information Disclosure Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-3255?
CVE-2016-3255 has a moderate severity rating due to its potential to allow information disclosure.
How do I fix CVE-2016-3255?
To fix CVE-2016-3255, update to the latest version of the Microsoft .NET Framework that is not affected by this vulnerability.
What systems are affected by CVE-2016-3255?
CVE-2016-3255 affects Microsoft .NET Framework versions 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1.
What type of attack does CVE-2016-3255 involve?
CVE-2016-3255 involves an XML External Entity (XXE) attack allowing remote attackers to read arbitrary files.
Is CVE-2016-3255 a local or remote vulnerability?
CVE-2016-3255 is a remote vulnerability that can be exploited without local access.