Summary
This host is missing an important security update according to Microsoft Bulletin MS13-013.
Impact
Successful exploitation could run arbitrary code in the context of a user account with a restricted token.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-013
Insight
The flaws are due to the error in Oracle Outside In libraries, when used by the Advanced Filter Pack while parsing specially crafted files.
Affected
Microsoft FAST Search Server 2010 for SharePoint Service Pack 1
References
Severity
Classification
-
CVE CVE-2012-3214, CVE-2012-3217 -
CVSS Base Score: 2.1
AV:L/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities
- Microsoft FAST Search Server 2010 SharePoint RCE Vulnerabilities (2784242)
- MS Exchange Server WebReady Document Viewing Remote Code Execution Vulnerabilities (2740358)
- Microsoft Windows Group Policy Security Feature Bypass Vulnerability (3004361)
- Microsoft FAST Search Server 2010 for SharePoint RCE Vulnerabilities (2742321)
- MS Exchange Server Remote Code Execution Vulnerabilities (2784126)