CERT-In Vulnerability Note
CIVN-2014-0254
Microsoft SharePoint Server Arbitrary Script Execution Vulnerability
Original Issue Date:November 12, 2014
Severity Rating: HIGH
Systems Affected
- Microsoft SharePoint Server 2010 Service Pack 2
Overview
A privilege elevation vulnerability has been reported in Microsoft SharePoint Server which could allow an authenticated remote attacker to gain elevated privileges leading to execution of arbitrary code.
Description
A privilege elevation vulnerability exist in Microsoft SharePoint Server due to improper sanitization of page content in SharePoints lists. An authenticated remote attacker could exploit this vulnerability by modifying certain lists in the SharePoint and convincing the logged-in user to open the list in the security context of a logged-on user.
Successful exploitation of this vulnerability could allow the attacker to gain elevated privileges of the system.
Solution
Apply appropriate patch as mention in Microsoft Security Bulletin
MS14-073
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-073.aspx
References
Security Focus
http://www.securityfocus.com/bid/70980
Security tracker
http://securitytracker.com/id/1031192
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36258
CVE Name
CVE-2014-4116
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|