Microsoft Office SharePoint Malformed Request Code Execution Vulnerability
Last Update Date:
28 Jan 2011
Release Date:
15 Dec 2010
5477
Views
RISK: Medium Risk
A remote code execution vulnerability exists in the way that the Document Conversions Launcher Service validates SOAP requests before processing on a SharePoint server. An attacker who successfully exploited this vulnerability could run arbitrary code on an affected SharePoint server under the security context of a guest account.
Impact
- Remote Code Execution
System / Technologies affected
- Microsoft Office SharePoint Server 2007
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
- Microsoft Office SharePoint Server 2007 Service Pack 2 (32-bit editions)
- Microsoft Office SharePoint Server 2007 Service Pack 2 (64-bit editions)
Vulnerability Identifier
Source
Related Link
Share with