Summary
This host is missing an important security update according to Microsoft Bulletin MS11-066.
Impact
Successful exploitation could allow attacker to gain access to sensitive information that may aid in further attacks.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://www.microsoft.com/technet/security/bulletin/ms11-066.mspx
Insight
The flaw is due to an error in the ASP.NET Chart controls when encountering special characters within a URI. This can be exploited to read the contents of arbitrary files in the web site directory or subdirectories via a specially crafted GET request to a server hosting the Chart controls.
Affected
Microsoft .NET Framework 4.0
Microsoft Chart Control for .NET Framework 3.5 SP1
References
Severity
Classification
-
CVE CVE-2011-1977 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:P/I:N/A:N
Related Vulnerabilities
- Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
- Microsoft JScript and VBScript Scripting Engines Information Disclosure Vulnerability (2475792)
- Microsoft Windows Active Directory SPN Denial of Service (2478953)
- Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
- Microsoft SharePoint Foundation Privilege Elevation Vulnerability (3000431)