Improper Restriction of XML External Entity Reference...
Moderate severity
Unreviewed
Published
Aug 31, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Aug 30, 2022
Published to the GitHub Advisory Database
Aug 31, 2022
Last updated
Feb 2, 2023
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
References