CRITICAL 9.1 Microsoft

CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

Microsoft Security Update 2024-Dec: In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.

Affected Products

References

Published: 2024-12-10 · Source: Microsoft · Feed updated: 2026-09-28
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-12-10 via Microsoft. Affected: azl3 libxml2 2.11.5-2 on Azure Linux 3.0, azl3 libxml2 2.11.5-5 on Azure Linux 3.0.

Risk Timeline

CVE Disclosed2024-12-10 · 657 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2024-56719net: stmmac: fix TSO DMA API usage causing oopsCRITICAL10.0
CVE-2026-44210Kata Containers have VM Escape via virtiofsd Argument Injection through Default-CRITICAL9.9
CVE-2026-78030DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_tyCRITICAL9.8
CVE-2026-85504FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsCRITICAL9.8
CVE-2026-85506ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_delCRITICAL9.8
CVE-2026-85507ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_CRITICAL9.8
vulnfeed aggregates 13625 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.