MS.MSXML.DTD.Cross.Domain.Scripting

Last Updated DateNov 24, 2009
Release DateNov 14, 2008
SeverityLow
ImpactInformation disclosure
DescriptionThis indicates a possible attempt to exploit an information disclosure vulnerability in Microsoft XML Core Services, which is caused by its way of handling error checks for external document type definitions. The vulnerability could lead to information disclosure or cross-domain attacks.
Affected ProductsMSXML versions prior to v6
Recommended ActionsApply the patch, available from the vendor's web site: http://www.microsoft.com/technet/security/Bulletin/MS08-069.mspx.
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-4029
Microsoft Bulletin IDMS08-069   http://www.microsoft.com/technet/security/Bulletin/ms08-069.mspx
Reference: VID-16123