Security research showed that Microsoft XMLDOM DTD validation in Internet Explorer could be abused to disclose limited client-side information through distinguishable error messages. By supplying external-entity-style references using formats such as UNC paths, file path variants, direct drive-letter paths, NTFS alternate data streams, and the res:// protocol, an attacker could infer whether local files, folders, drive letters, network shares, and some local hosts existed on the victim system.
The reported behavior did not provide reliable arbitrary file-content disclosure, but it enabled existence checks and some local network probing based on error differences and response timing. Proof-of-concept pages were published to demonstrate the issue, and the researcher also noted that XMLDOM's DTD parsing behavior appeared susceptible to denial of service, characterizing the overall finding as a low-impact, Internet Explorer client-side information disclosure issue.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The researcher published proof-of-concept pages showing how UNC paths, file path variants, NTFS alternate data streams, direct drive references, and the res:// protocol could be used to trigger informative errors in IE XMLDOM. The write-up also noted apparent denial-of-service behavior related to DTD parsing.
Security research found that Microsoft XMLDOM DTD validation in Internet Explorer returned distinguishable error messages for different path types, allowing limited inference about the existence of local files, folders, drive letters, network shares, and some local hosts. The issue was characterized as a low-impact, client-side information disclosure rather than arbitrary file read.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.