Impact
Exterro FTK Imager contains an XML external entity injection flaw that allows a malicious Report.xml file to reference arbitrary files via file:// URIs and embed attacker‑controlled XSLT in the external stylesheet. When the evidence is previewed, the parser resolves these entities and can exfiltrate the file contents through an attacker‑controlled endpoint, effectively leaking sensitive data from the host system. This weakness is characterized by CWE-611 (XML External Entity) and CWE-829 (Exposing Data to an Unauthorized Actor).
Affected Systems
Exterro FTK Imager versions prior to 8.3 are impacted. The vulnerability exists in all builds below the 8.3 release.
Risk and Exploitability
The CVSS score of 6.8 signifies a moderate severity. The EPSS score is not available, leaving the exact exploitation probability uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted UFDR archive that an examiner opens; the exploit requires the victim to preview the malicious XML, so it is a user‑action or local‑execution model rather than a remotely triggered network exploit.
OpenCVE Enrichment