CRITICAL 9.8 Microsoft PoC
CVE-2022-25236
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Microsoft Security Update 2022-Feb: xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
Affected Products
- cm1 expat 2.4.6-1 on CBL Mariner 1.0
- cbl2 expat 2.4.8-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-25236
- https://nvd.nist.gov/vuln/detail/CVE-2022-25236
This critical severity vulnerability with a CVSS score of 9.8 was published on 2022-02-08 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 35.9% (top 2% of all CVEs by exploitation probability). Affected: cm1 expat 2.4.6-1 on CBL Mariner 1.0, cbl2 expat 2.4.8-1 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2022-02-08 · 1671 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-25236NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2022-25236Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2021-3773 PoC | A flaw in netfilter could allow a network-connected attacker to infer openvpn co | CRITICAL | 9.8 |
| CVE-2022-25235 PoC | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of e | CRITICAL | 9.8 |
| CVE-2022-25315 PoC | In Expat (aka libexpat) before 2.4.5 there is an integer overflow in storeRawNam | CRITICAL | 9.8 |
| CVE-2022-23806 | Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 | CRITICAL | 9.1 |
| CVE-2021-4093 | A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtu | HIGH | 8.8 |
| CVE-2021-4154 | A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v | HIGH | 8.8 |
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.