Microsoft HTML Sanitization Component Elevation of Privilege Vulnerability
Last Update Date:
10 Apr 2013 12:31
Release Date:
10 Apr 2013
4013
Views
RISK: High Risk
TYPE: Operating Systems - Windows OS
An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks on affected systems and run script in the security context of the current user.
Impact
- Cross-Site Scripting
- Elevation of Privilege
System / Technologies affected
- Microsoft InfoPath 2010 Service Pack 1
- Microsoft SharePoint Server 2010 Service Pack 1
- Microsoft Groove Server 2010 Service Pack 1
- Microsoft SharePoint Foundation 2010 Service Pack 1
- Microsoft Office Web Apps 2010 Service Pack 1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-035
Vulnerability Identifier
Source
Related Link
Share with