Microsoft SharePoint Server Remote Code Execution Vulnerabilities
RISK: High Risk
TYPE: Servers - Other Servers
Related remote code execution vulnerabilities exist in Microsoft SharePoint Server and Microsoft Web Applications. An authenticated attacker who successfully exploited any of these related vulnerabilities could run arbitrary code in the security context of the W3WP service account.
An elevation of privilege vulnerability exists in Microsoft SharePoint Server. An attacker who successfully exploited this vulnerability could perform cross-site scripting attacks on affected systems and run script in the security context of the logged-on user.
Impact
- Elevation of Privilege
- Remote Code Execution
System / Technologies affected
- Microsoft SharePoint Server 2007
- Microsoft SharePoint Server 2010
- Microsoft SharePoint Server 2013
- Microsoft Office Web Apps 2010
- Microsoft Office Web Apps 2013
- SharePoint Server 2013 Client Components SDK
- Microsoft SharePoint Designer 2007
- Microsoft SharePoint Designer 2010
- Microsoft SharePoint Designer 2013
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/MS14-022
Vulnerability Identifier
Source
Related Link
Share with