CVE Vulnerabilities

CVE-2018-8420

Improper Restriction of XML External Entity Reference

Published: Sep 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka MS XML Remote Code Execution Vulnerability. This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

NameVendorStart VersionEnd Version
Windows_10Microsoft- (including)- (including)
Windows_10Microsoft1607 (including)1607 (including)
Windows_10Microsoft1703 (including)1703 (including)
Windows_10Microsoft1709 (including)1709 (including)
Windows_10Microsoft1803 (including)1803 (including)
Windows_7Microsoft–sp1 (including)–sp1 (including)
Windows_8.1Microsoft- (including)- (including)
Windows_serverMicrosoft2008-r2 (including)2008-r2 (including)
Windows_serverMicrosoft2008-sp2 (including)2008-sp2 (including)
Windows_serverMicrosoft2012 (including)2012 (including)
Windows_serverMicrosoft2012-r2 (including)2012-r2 (including)
Windows_serverMicrosoft2016 (including)2016 (including)
Windows_serverMicrosoft2016-1709 (including)2016-1709 (including)
Windows_serverMicrosoft2016-1803 (including)2016-1803 (including)

Potential Mitigations

References