logo

MS Threat Modeller

ID: 3a505089-82ec-5aab-8d5f-2ab9940ef198

STIX ID: report--3a505089-82ec-5aab-8d5f-2ab9940ef198

Feed Name: SensePost Blog

Threat Score
30/100

Date Published: 2009-09-15

Date Updated: 2026-04-29

...
...

SensePost researchers discovered cross-site scripting in Microsoft's Threat Modeller that, when combined with vulnerable ActiveX controls and file:// usage, can be chained to achieve remote code execution; the issue was reported to Microsoft, which declined to investigate further because the product is deprecated and the download was removed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.