CERT-In Vulnerability Note
CIVN-2012-0087
Microsoft System Center Configuration Manager XSS Vulnerability
Original Issue Date:September 12, 2012
Severity Rating: MEDIUM
Systems Affected
- Microsoft Systems Management Server 2003 SP 3
- Microsoft System Center Configuration Manager 2007 SP 2
Overview
An elevation of privilege vulnerability has been reported in Microsoft System Center Configuration Manager, which could be exploited by remote attackers to conduct reflected XSS attacks.
Description
System Center Configuration Manager (SCCM) helps organizations maintain corporate compliance by managing physical, virtual, and mobile clients with things like application delivery, desktop virtualization and security.
The vulnerability exists because the SCCM administrative user interface does not properly filter HTML code from user-supplied input before displaying the input. A remote attacker could exploit this issue by enticing a target user to open a specially crafted web page. Successful exploitation could allow an attacker to spoof content, disclose information, or take any action that the user could take on the affected website on behalf of the targeted user.
Solution
Apply appropriate security updates as mentioned in Microsoft Security Bulletin
MS12-062
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-062
References
Secunia
http://secunia.com/advisories/50497/
SecurityFocus
http://www.securityfocus.com/bid/55430
SecurityTracker
http://www.securitytracker.com/id/1027512
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-062
CVE Name
CVE-2012-2536
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|