Summary
This host is missing an important security update according to Microsoft Bulletin MS11-067.
Impact
Successful exploitation will let the attacker execute arbitrary HTML and script code in a user's browser session in context of an affected site.
Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link.
http://www.microsoft.com/technet/security/bulletin/ms11-067.mspx
Insight
A flaw is due to an unspecified input passed to the Microsoft Report Viewer Control is not properly sanitised before being returned to the user.
Affected
Microsoft Visual Studio 2005 Service Pack 1
Microsoft Report Viewer 2005 Service Pack 1 Re-distributable Package
References
Severity
Classification
-
CVE CVE-2011-1976 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities
- Microsoft .NET Framework Denial of Service Vulnerability (2990931)
- Microsoft SharePoint Foundation Privilege Elevation Vulnerability (3000431)
- Microsoft Windows Media Center Remote Code Execution Vulnerability (2978742)
- Microsoft SharePoint Server HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft Office Web Apps HTML Sanitisation Component XSS Vulnerability (2821818)