LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-0022: Microsoft XML Core Services Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 24, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 14, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-0022 to its Known Exploited Vulnerabilities catalog on May 24, 2022, with a federal patch deadline of Jun 14, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

CVE-2017-0022 is an information disclosure vulnerability in Microsoft XML Core Services (MSXML). The component improperly handles objects in memory, which can let an attacker use a crafted website to test for the presence of files on disk. For IT and security teams this matters because successful abuse can reveal filesystem details that aid further targeting, even though the flaw itself is not described as direct code execution.

Public detail is limited to the CISA summary and the CWE-200 classification. Confirm exact affected products, versions, and patch identifiers against the vendor advisory before acting.

How it works

This issue falls under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). MSXML mishandles objects in memory. An attacker who can entice a user to visit a crafted website can leverage that mishandling to probe whether specific files exist on the local disk. The result is information disclosure rather than arbitrary code execution. Exact exploit mechanics beyond the CISA description are not provided here; treat any public proof-of-concept claims with caution and validate them against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft XML Core Services is a Windows component commonly used by applications and browsers that process XML. It typically appears on client and server Windows systems where MSXML libraries are installed or registered.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities can lead to broader compromise even when the initial flaw only discloses information. Known ransomware use of this CVE is not documented in the provided facts. If you suspect exposure, follow your incident-response process: isolate affected hosts, preserve logs, and assess whether any disclosed paths enabled follow-on access. You can also run a free exposure scan of your email addresses against known breach data to check for unrelated credential leaks that might compound risk.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · XML Core Services
WeaknessCWE-200
Added to CISA KEVMay 24, 2022
Federal patch deadlineJun 14, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities