Synced 17 Jun 2026 15:03 UTC Account
← All products

CVE-2014-1816

MEDIUM severity · CVSS 4.3 · CWE-264
4.3CVSS MEDIUM

Summary

Microsoft XML Core Services (aka MSXML) 3.0 and 6.0 does not properly restrict the information transmitted by Internet Explorer during a download action, which allows remote attackers to discover (1) full pathnames on the client system and (2) local usernames embedded in these pathnames via a crafted web site, aka "MSXML Entity URI Vulnerability."

Impact & exploitability

Attack vectorNetwork
Attack complexity
Privileges required
User interaction
Confidentiality impact
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)14%

AV:N/AC:M/Au:N/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.