CVE-2024-9044: Msg Suisse AG Easytax

Medium severity, CVSS 4.6. EPSS: 0.2% chance of exploitation in the next 30 days.

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

Affected products

  • Msg Suisse AG Easytax: from 2023, up to and including 1.2; from 2022, up to and including 1.3; up to and including 2021

Published 2024-11-29. Last modified 2026-06-17.