Summary
This host is missing an important security update according to Microsoft Bulletin MS12-066.
Impact
Successful exploitation could allow an attacker to bypass certain security restrictions and conduct cross-site scripting and spoofing attacks.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms12-066
Insight
Certain unspecified input is not properly sanitised within the HTML Sanitisation component before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Affected
Microsoft Lync 2010
Microsoft Lync 2010 Attendee
Microsoft Communicator 2007 R2
Microsoft InfoPath 2007 Service Pack 2
Microsoft InfoPath 2007 Service Pack 3
Microsoft InfoPath 2010 Service Pack 1
Microsoft Groove Server 2010 Service Pack 1
Microsoft Office Web Apps 2010 Service Pack 1
Microsoft SharePoint Server 2010 Service Pack 1
Microsoft SharePoint Server 2007 Service Pack 2
Microsoft SharePoint Server 2007 Service Pack 3
Microsoft SharePoint Foundation 2010 Service Pack 1 Microsoft Windows SharePoint Services 3.0 Service Pack 2
References
Severity
Classification
-
CVE CVE-2012-2520 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
- Microsoft Office Shared Component Security Bypass Vulnerability (2905238)
- Exchange 2000 Exhaust CPU Resources (Q320436)
- Microsoft Groove Server HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft Window XML Core Services Information Disclosure Vulnerability (2966061)