Skip to main content

Microsoft Office and SharePoint Products HTML Sanitization Vulnerability

Last Update Date: 10 Oct 2012 15:39 Release Date: 10 Oct 2012 4808 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Microsoft Office 2007
  • Microsoft Office 2010
  • Microsoft Communicator 2007 R2
  • Microsoft Lync 2010 (32-bit)
  • Microsoft SharePoint Server 2007
  • Microsoft SharePoint Server 2010
  • Microsoft Groove Server 2010
  • Microsoft Windows SharePoint Services 3.0
  • Microsoft SharePoint Foundation 2010
  • Microsoft Office Web Apps 2010

Solutions

 Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link