Microsoft SharePoint Server Privilege Elevation Vulnerabilities (2780176)

Summary
This host is missing a critical security update according to Microsoft Bulletin MS13-024.
Impact
Successful exploitation could allow an attacker to bypass certain security restrictions, disclose certain system data and conduct cross-site scripting and spoofing attacks. Impact Level: Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms13-0-24
Insight
- The application allows users to perform certain actions via HTTP requests without performing proper validity checks to verify the requests. - Certain unspecified input is not properly sanitized before being returned to the user. - An error related to the W3WP process when handling URLs can be exploited to cause a buffer overflow and subsequently terminate the W3WP process via a specially crafted URL.
Affected
Microsoft SharePoint Server 2010 Service Pack 1 Microsoft SharePoint Foundation 2010 Service Pack 1
References