Microsoft Office and SharePoint Products HTML Sanitization Vulnerability
Last Update Date:
10 Oct 2012 15:39
Release Date:
10 Oct 2012
5346
Views
RISK: High Risk
TYPE: Clients - Productivity Products
An elevation of privilege vulnerability exists in the way that HTML strings are sanitized. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.
Impact
- Elevation of Privilege
System / Technologies affected
- Microsoft Office 2007
- Microsoft Office 2010
- Microsoft Communicator 2007 R2
- Microsoft Lync 2010 (32-bit)
- Microsoft SharePoint Server 2007
- Microsoft SharePoint Server 2010
- Microsoft Groove Server 2010
- Microsoft Windows SharePoint Services 3.0
- Microsoft SharePoint Foundation 2010
- Microsoft Office Web Apps 2010
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-064
Vulnerability Identifier
Source
Related Link
Share with