Description
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34599 | Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly. |
References
History
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-03T00:32:09.692Z
Reserved: 2022-07-06T00:00:00.000Z
Link: CVE-2022-2330
No data.
Status : Modified
Published: 2022-08-30T08:15:07.453
Modified: 2024-11-21T07:00:46.970
Link: CVE-2022-2330
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD