You are viewing this page in an unauthorized frame window.
This is a potential security issue, you are being redirected to
https://nvd.nist.gov
An official website of the United States government
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock () or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes XML Notepad to make outbound HTTP/SMB requests, potentially leaking local file contents or capturing the victim's NTLM credentials. This issue has been patched in version 2.9.0.21.
Metrics
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected].
Title: XmlNotepad de microsoft, Description: XML Notepad es un programa de Windows que proporciona una interfaz de usuario sencilla e intuitiva para navegar y editar documentos XML. Antes de la versión 2.9.0.21, XML Notepad no deshabilita el procesamiento de DTD por defecto, lo que significa que las entidades externas se resuelven automáticamente. Existe un ataque bien conocido relacionado con archivos DTD maliciosos donde un atacante puede crear un archivo XML malicioso que carga un DTD que hace que XML Notepad realice solicitudes HTTP/SMB salientes, potencialmente filtrando el contenido de archivos locales o capturando las credenciales NTLM de la víctima. Este problema ha sido parcheado en la versión 2.9.0.21.
New CVE Received from GitHub, Inc.3/31/2026 6:16:18 PM
Action
Type
Old Value
New Value
Added
Description
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes XML Notepad to make outbound HTTP/SMB requests, potentially leaking local file contents or capturing the victim's NTLM credentials. This issue has been patched in version 2.9.0.21.