Skip to main content

Microsoft SharePoint Server Remote Code Execution Vulnerabilities

Last Update Date: 9 Oct 2013 18:57 Release Date: 9 Oct 2013 3691 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers
  1. Microsoft Excel Memory Corruption Vulnerability
    A remote code execution vulnerability exists in the way that affected Microsoft Office Services and Web Apps parse content in specially crafted files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
  2. Parameter Injection Vulnerability
    An elevation of privilege vulnerability exists in Microsoft SharePoint Server. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks and run script in the security context of the logged-on user.

Impact

  • Cross-Site Scripting
  • Elevation of Privilege
  • Remote Code Execution

System / Technologies affected

  • Microsoft SharePoint Server 2007
  • Microsoft SharePoint Server 2010
  • Microsoft SharePoint Server 2013
  • Microsoft Office Web Apps 2010

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link