Skip to main content

Microsoft HTML Sanitization Component Elevation of Privilege Vulnerability

Last Update Date: 10 Apr 2013 12:31 Release Date: 10 Apr 2013 4013 Views

RISK: High Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks on affected systems and run script in the security context of the current user.


Impact

  • Cross-Site Scripting
  • Elevation of Privilege

System / Technologies affected

  • Microsoft InfoPath 2010 Service Pack 1
  • Microsoft SharePoint Server 2010 Service Pack 1
  • Microsoft Groove Server 2010 Service Pack 1 
  • Microsoft SharePoint Foundation 2010 Service Pack 1
  • Microsoft Office Web Apps 2010 Service Pack 1

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link