Microsoft Windows Active Directory Certificate Services Vulnerability
Last Update Date:
15 Jun 2011 14:19
Release Date:
15 Jun 2011
6504
Views
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A reflected XSS vulnerability exists in Active Directory Certificate Services Web Enrollment that could allow an attacker to inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the site on behalf of the targeted user.
Impact
- Elevation of Privilege
System / Technologies affected
- Windows Server 2003
- Windows Server 2008
- Windows Server 2008 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://www.microsoft.com/technet/security/Bulletin/MS11-051.mspx
Vulnerability Identifier
Source
Related Link
Share with