CVE-2018-25282
MEDIUMNmap 7.70 Denial of Service via XML Entity Expansion
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25282. PoCs published by Gionathan Reale.
AI-analyzed exploit summary This PoC exploits an XML Entity Expansion (XEE) vulnerability in Nmap 7.70 (ZenMap) by using a maliciously crafted XML file with recursive entity references, leading to a denial of service (DoS) due to excessive resource consumption.
Description
Nmap 7.70 contains a denial of service vulnerability that allows local attackers to crash the application by processing malicious XML files with exponential entity expansion. Attackers can create a crafted XML file with nested entity definitions and open it through ZenMap's scan import functionality to cause the program to consume excessive system resources and crash.
Exploits (1)
This PoC exploits an XML Entity Expansion (XEE) vulnerability in Nmap 7.70 (ZenMap) by using a maliciously crafted XML file with recursive entity references, leading to a denial of service (DoS) due to excessive resource consumption.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H