CVE-2017-0022

MEDIUM(6.5)KEVElevated Risk

Microsoft XML Core Services Information Disclosure Vulnerability

Description

CVE-2017-0022 is an information disclosure vulnerability in Microsoft XML Core Services (MSXML) that allows attackers to detect the presence of specific files on a user's system. The vulnerability arises from improper handling of objects in memory, which can be triggered by luring a user to a crafted website. Successful exploitation enables an attacker to enumerate files on disk, gathering reconnaissance information that can be used to plan further attacks. CVE-2017-0022 has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, and its EPSS percentile of 97.4% indicates a very high likelihood of exploitation.

KEV Information

Vendor
Microsoft
Product
XML Core Services
Date Added
May 24, 2022
Due Date
June 14, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
microsoftxml core services3.0
microsoftwindows 8.1-
microsoftwindows server 2008r2
microsoftwindows server 2012-; r2

Multiple CVSS Assessments

Source: [email protected](Primary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
6.5
MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

References

Weakness Type

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CWE-200 describes weaknesses where a product unintentionally exposes sensitive information to unauthorized parties. In CVE-2017-0022, the Microsoft XML Core Services component mishandles memory objects during XML processing, enabling remote attackers to probe for the existence of specific files on the target system through a specially crafted website. This file enumeration capability provides attackers with valuable reconnaissance data.

Learn more: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor

Impact Analysis

CVE-2017-0022 primarily impacts confidentiality by allowing attackers to determine whether specific files exist on a target system. Although the direct impact is limited to information disclosure rather than code execution, this reconnaissance capability is highly valuable for attackers planning targeted attacks. The vulnerability is exploitable remotely through a crafted web page, requiring user interaction in the form of visiting a malicious website. The EPSS percentile of 97.4% reflects significant real-world exploitation, as this type of file detection vulnerability is commonly used in exploit kits to fingerprint target systems and select appropriate follow-up payloads. CISA's inclusion in the KEV catalog confirms that this vulnerability has been actively exploited in the wild.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2017-0022 in the wild and added it to the Known Exploited Vulnerabilities catalog with a remediation deadline of June 14, 2022. The EPSS percentile of 97.4% indicates very high exploitation probability, consistent with its known use in exploit kits for target fingerprinting. This vulnerability was notably used in AdGholas and other malvertising campaigns to detect security research tools and virtual machine artifacts on target systems before delivering exploit payloads, making it a key component in evasion-aware exploit chains.

Remediation

  1. Apply security updates from Microsoft as directed by the vendor. This is the primary remediation action required by CISA's KEV catalog entry for CVE-2017-0022.
  2. Ensure that Microsoft XML Core Services (MSXML) is updated to the latest patched version across all affected systems, including those running Internet Explorer and Microsoft Office.
  3. Implement browser hardening measures such as disabling ActiveX controls and restricting the execution of scripts from untrusted sources to reduce the attack surface for web-based exploitation.
  4. Deploy web filtering or proxy solutions to block access to known malicious domains associated with exploit kit campaigns that leverage CVE-2017-0022.
  5. Monitor endpoint security logs for indicators of MSXML exploitation, including unusual XML processing activity or attempts to probe for file existence on disk.

Technical Details

CVE-2017-0022 exploits a flaw in how Microsoft XML Core Services (MSXML) handles objects in memory during XML document processing. When a user visits a crafted website containing malicious XML content, the MSXML parser improperly processes certain memory objects, creating a side channel that allows the attacker to determine whether specific files exist on the victim's local file system. This information disclosure mechanism falls under CWE-200, where the application inadvertently reveals sensitive system information to an unauthorized remote party. The attack requires network access and user interaction (visiting a malicious page), but no authentication is needed. This vulnerability was particularly valuable in exploit kit operations, where attackers used the file detection capability to check for the presence of security tools, virtual machine indicators, or specific software versions before deciding whether to deliver a full exploit payload.

Frequently Asked Questions

Is CVE-2017-0022 being actively exploited?

Yes, CVE-2017-0022 has been actively exploited in the wild. CISA has confirmed active exploitation and added it to the Known Exploited Vulnerabilities catalog. The EPSS percentile of 97.4% reflects very high real-world exploitation activity, driven by its use in exploit kits and malvertising campaigns.

What products are affected by CVE-2017-0022?

CVE-2017-0022 affects Microsoft XML Core Services (MSXML), which is a component used by Internet Explorer and other Microsoft products. Multiple versions of Windows and Internet Explorer that rely on MSXML for XML processing are potentially affected.

How do I fix CVE-2017-0022?

Apply the relevant Microsoft security updates for MSXML as directed by the vendor. Additionally, implement browser hardening measures such as disabling ActiveX controls and restricting scripts from untrusted sources. See the Remediation section for detailed guidance.

How severe is CVE-2017-0022?

CVE-2017-0022 is an information disclosure vulnerability that allows file enumeration on target systems. While not directly enabling code execution, its EPSS percentile of 97.4% reflects high exploitation activity due to its use as a reconnaissance tool in exploit kit campaigns, making it a significant risk when unpatched.

CVSS Score

6.5
MEDIUM(6.5)

EPSS Score

EPSS Score18.07%
EPSS Percentile97.0%

Dates

PublishedMarch 17, 2017
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.