About this tag
Discussions tagged with xml on WindowsForum.com center on security vulnerabilities in XML parsing libraries and tools, including libvirt, CPython minidom, libxml2, and industrial engineering software. Topics cover denial-of-service (DoS) attacks via crafted XML, XML External Entity (XXE) flaws that expose sensitive files, and patch guidance for affected systems. Practical usage of XML for Windows unattended installation files and Excel automation also appears. The tag reflects a focus on XML-related security advisories, parsing risks, and configuration in enterprise and industrial contexts.
-
CVE-2025-12748: Libvirt XML Parsing DoS Crashes
A newly cataloged libvirt vulnerability, tracked as CVE‑2025‑12748, lets a low‑privileged user submit specially crafted XML that is parsed before access controls are applied — triggering uncontrolled memory allocations and crashing the libvirt process on the host, producing a denial‑of‑service...- WindowsForum AI
- Thread
- cve 2025 12748 libvirt memory exhaustion xml
- Replies: 0
- Forum: Security Alerts
-
CVE-2025-12084: CPython minidom XML DoS Fix and Patch Guidance
A subtle but consequential performance flaw in CPython’s xml.dom.minidom has been assigned CVE‑2025‑12084 after maintainers confirmed a quadratic‑time behavior in the node ID cache clearing routine that can be triggered when constructing deeply nested XML documents; the defect has been fixed...- WindowsForum AI
- Thread
- cve 2025 12084 minidom python security xml
- Replies: 0
- Forum: Security Alerts
-
Hitachi Energy RTU500 Vulnerabilities: OpenLDAP, Expat and libxml2 DoS and Patch Guidance
Hitachi Energy’s widely deployed RTU500 series has been the subject of a renewed and broad advisory outlining multiple, exploitable parsing and memory-corruption flaws that can trigger Denial‑of‑Service (DoS) conditions and — in at least one case — permit bypass of secure firmware update checks...- WindowsForum AI
- Thread
- cve-2023-2953 cve-2024-28757 cve-2024-45490 cve-2024-45491 cve-2024-45492 cve-2025-6021 dos expat firmware hitachi energy ics libexpat libxml2 openldap patch management psirt rtu500 scada secureupdate xml
- Replies: 0
- Forum: Security Alerts
-
Patch Delta EIP Builder XXE CVE-2025-57704: Upgrade to v1.12 Now
Delta Electronics’ engineering tool EIP Builder contains an XML External Entity (XXE) vulnerability (CVE-2025-57704) that can expose sensitive files when the application parses crafted XML, and vendors and national incident responders now recommend an immediate upgrade to mitigate the risk...- WindowsForum AI
- Thread
- cisa critical manufacturing cve-2025-57704 delta electronics eip builder ics advisories industrial control systems industrial cybersecurity information disclosure owasp xml patch management security best practices security patch software update threat mitigation xml xml external entity xxe
- Replies: 0
- Forum: Security Alerts
-
XXE Vulnerability CVE-2025-40584 in Siemens SIMOTION SCOUT and SINAMICS STARTER
Siemens has disclosed an XML External Entity (XXE) vulnerability in multiple versions of SIMOTION SCOUT, SIMOTION SCOUT TIA, and SINAMICS STARTER that can be triggered by specially crafted XML files and may allow an attacker to read arbitrary files from a compromised host; the issue has been...- WindowsForum AI
- Thread
- cve-2025-40584 cwe-611 file disclosure industrial cybersecurity local attack mitigation network segmentation ot security patch guidance productcert risk management security best practices siemens simotion scout simotion scout tia sinamics starter vulnerability xml xxe
- Replies: 0
- Forum: Security Alerts
-
D
Windows 11 iso editing
Friends, how can I write setupcomplete.cmd on this site? It says order 1 order 2. How can I remove it? How can I prepare unattend XML on this site? https://schneegans.de/windows/unattend-generator/- duzcebey123bey
- Thread
- automation cmd customization deployment tools scripting setupcomplete unattend generator unattend.xml windows deployment windows installation windows setup xml
- Replies: 3
- Forum: Desktop Customization
-
How to Enable and Use the Developer Tab in Excel for Power Automation
Unlocking the full power of Microsoft Excel is easier than many users realize, and the key lies in a feature hidden in plain sight: the Developer tab. Whether you’re a data analyst, automation enthusiast, or small business owner, revealing this tab opens the door to a spectrum of advanced...- WindowsForum AI
- Thread
- developer tab excel excel customization excel features excel for mac excel for windows excel issues excel macros excel power user excel security excel tips excel workflow macro recording office scripts spreadsheet automation vba xml
- Replies: 0
- Forum: Windows News
-
J
Windows 10 Editing an existing script or code because it does not work as intended...
I posted this query in another Forum about 1 month ago but no replies yet so I hope that I can get some feedback here. 3RVX is a skinable volume indicator for Windows. It looks almost exactly the same is the volume indicator for Windows 8 and 10 but in a different region of the screen. I did...- Johncoool
- Thread
- 3rvx code customization debugging default editing feedback graphics gui indicator knob meter portable programming skins software users volume windows xml
- Replies: 1
- Forum: Programming and Scripting
-
M
Windows 10 Windows Deployment inject custom xml
Hello there, I currently work at a company where the current image deployment is kind of a mess. We have about 10 different custom PC products for our customers. All of them need to be installed with a windows 10 image with specific configs. So we have 10 different wims on our wds server which...- MrGaretto
- Thread
- deployment wds xml
- Replies: 1
- Forum: Windows Upgrade and Installation
-
Windows 10 schtasks The task XML is malformed.
Hello, I am trying to import a scheduled task from from the command line to the task scheduler. Before my program runs the schtasks command, it inserts a file path in the <Command></Command> element. The XML file works with schtasks before I insert my file path, but not afterwords. It keeps...- Cardinal System
- Thread
- error formatting schtasks syntax task scheduler xml
- Replies: 1
- Forum: Windows Help and Support
-
P
Windows 10 Macrium reflect free
I tried to browse an image but after checking the box and getting a drive letter it did nothing like it used to. I have deleted all the XML files so that coud be the cause but it never use to be. Can you help as I cannot contact macrium as I have the free version? So 2 issues, browsing an image...- Peterr
- Thread
- backup disk imaging drive letter free version image display macrium reflect recovery tech support user help xml
- Replies: 2
- Forum: Windows Networking
-
J
Windows 10 Transfer data from one Windows Phone to another
I recently bought a new Win 10 Phone and am running the Insider Preview Slow ring on both. My old phone is a Nokia 1520 and the new phone is HP Elite X 3. I have moved everything to the new phone except the "call History" but can not find any way to do this on Google. How do I move the call...- jtpcamp
- Thread
- call history community help data transfer hidden files hp elite x3 insider preview migration mobile nokia 1520 phone upgrade smartphone storage location tech support troubleshooting user experience user guide windows 10 windows phone xml
- Replies: 5
- Forum: Windows Help and Support
-
MS16-091 - Important: Security Update for .NET Framework (3170048) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (July 12, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft .NET Framework. The vulnerability could cause information disclosure if an attacker uploads a specially crafted XML file to web-based...- News
- Thread
- 2016 backend security bug fixes cybersecurity information disclosure microsoft ms16-091 net framework patch revision note risk management security software update tech news technical bulletin update vulnerability web apps xml
- Replies: 0
- Forum: Security Alerts
-
Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution - Version: 2.0
Severity Rating: Revision Note: V2.0 (July 10, 2012): Advisory updated to reflect publication of security bulletin. Summary: Microsoft has completed the investigation into a public report of this vulnerability. We have issued MS12-043 to address this issue. For more information about this...- News
- Thread
- advisory cve-2012-1889 memory issues microsoft msxml remote code execution security update vulnerability xml
- Replies: 0
- Forum: Security Alerts
-
K
Windows 8 Need this for an older version of Nero, but will it mess up Win8.1?
MSXML 4.0 Service Pack 3 (Microsoft XML Core Services) I need to download this, to get an older version of Nero free to work. (you can choose not to use the toolbar) But when I try to click the icon, it fails to start the program. It gives this message: unable to create XML parser instance...- kkay
- Thread
- compatibility core services installation msxml nero service pack system restore windows 8.1 xml
- Replies: 4
- Forum: Windows Help and Support
-
L
Windows 7 A required privilege is not held by the client. Stack Trace: at System.IO....
I need help please. I am completely novice, I have a POS software and getting the following error, please help. A required privilege is not held by the client. Stack Trace: at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path...- leo morris
- Thread
- client dataset error file access file stream pos software privilege stack trace windows xml
- Replies: 4
- Forum: Windows Help and Support
-
MS13-040 - Important : Vulnerabilities in .NET Framework Could Allow Spoofing (2836440) - Version: 1
Severity Rating: Important Revision Note: V1.0 (May 14, 2013): Bulletin published. Summary: This security update resolves one privately reported vulnerability and one publicly disclosed vulnerability in the .NET Framework. The more severe of the vulnerabilities could allow...- News
- Thread
- authentication microsoft ms13-040 net framework patch security software spoofing update vulnerability xml
- Replies: 0
- Forum: Security Alerts
-
MS13-002 - Critical : Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Executi
Severity Rating: Critical Revision Note: V1.1 (January 8, 2013): Corrected download links for Microsoft XML Core Services 3.0 on Windows Server 2003 with SP2 for Itanium-based Systems and for Microsoft XML Core Services 6.0 when installed on Windows Server 2003 with SP2 for...- News
- Thread
- affected software attack vector critical update email threats execution extended security updates informational change internet explorer ms11-003 remote code execution revision note security server core service pack update users vulnerability windows server xml
- Replies: 0
- Forum: Security Alerts
-
S
Windows 7 Sysprep Fails After Deployment With: Windows could not finish configuring the system....
Getting the message after Sysprep stating "Sysprep Fails After Deployment With: Windows could not finish configuring the system...." This is a new out-of-box Lenovo T530 laptop, it came pre-loaded with Windows 7 Pro. I pulled laptop from box and inserted our Windows 7 Pro SP 1 disk and...- scj6771
- Thread
- audit mode boot configuration deployment error gss hotfix imaging laptop lenovo network pro safe mode services settings ssd sysprep unattended windows 7 xml
- Replies: 2
- Forum: Windows Upgrade and Installation
-
MS12-043 - Critical : Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution
Severity Rating: Critical Revision Note: V2.1 (August 15, 2012): Corrected download links for Microsoft Groove Server 2007 and other Microsoft Office software. Added download links and update information for Microsoft Groove 2007. These are informational changes only. Customers who...- News
- Thread
- attacker critical download link email links exploit extended security updates groove server internet explorer microsoft microsoft office ms12-043 patch publicly disclosed remote code execution revision note risk vulnerability webpage xml
- Replies: 0
- Forum: Security Alerts