CERT-In Vulnerability Note
CIVN-2012-0100
Microsoft Products HTML Processing Cross-Site Scripting Vulnerability
Original Issue Date:October 10, 2012
Severity Rating: HIGH
Systems Affected
- Microsoft InfoPath 2007 SP2
- Microsoft InfoPath 2007 SP3
- Microsoft InfoPath 2010 SP1 (32-bit & 64-bit edition)
- Microsoft Communicator 2007 R2
- Microsoft Lync 2010 (32-bit & 64-bit)
- Microsoft Lync 2010 Attendee
- Microsoft SharePoint Server 2007 SP2 (32-bit) & SP3 (32-bit & 64-bit edition)
- Microsoft SharePoint Server 2010 SP1
- Microsoft Groove Server 2010 SP1
- Microsoft Windows SharePoint Services 3.0 SP2 (32-bit & 64-bit edition)
- Microsoft SharePoint Foundation 2010 SP1
- Microsoft Office Web Apps 2010 SP1
Overview
A vulnerability has been reported in multiple Microsoft products that could allow a remote attacker to execute arbitrary HTML scripting code to conduct cross-site scripting attacks.
Description
This vulnerability is due to improper filtering of HTML code via HTML sanitizer from user-supplied input. An unauthenticated, remote attacker could exploit this vulnerability by convincing a user to follow a crafted URL that is designed to submit malicious input to the vulnerable script which is to be executed by the target user¿s browser .
Successful exploitation could allow the attacker to execute arbitrary script code in the context of the affected site and access to sensitive browser-based information.
Solution
Apply appropriate security updates as mentioned in Microsoft Security Bulletin
MS12-066
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-066
References
Microsoft
http://technet.microsoft.com/en-us/security/bulletin/ms12-066
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=27089
Security tracker
http://www.securitytracker.com/id/1027627
CVE Name
CVE-2012-2520
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|