Skip to main content

Microsoft Office SharePoint Malformed Request Code Execution Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 15 Dec 2010 4806 Views

RISK: Medium Risk

A remote code execution vulnerability exists in the way that the Document Conversions Launcher Service validates SOAP requests before processing on a SharePoint server. An attacker who successfully exploited this vulnerability could run arbitrary code on an affected SharePoint server under the security context of a guest account.


Impact

  • Remote Code Execution

System / Technologies affected

  • Microsoft Office SharePoint Server 2007

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

Download locations for this patch


Vulnerability Identifier


Source


Related Link