Summary
This host is missing an important security update according to Microsoft Bulletin MS12-021.
Impact
Successful exploitation could allow attacker to execute arbitrary code with elevated privileges.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://technet.microsoft.com/en-us/security/bulletin/ms12-021
Insight
The flaw is due to the application loading add-ins from insecure paths.
This can be exploited to gain additional privileges by placing malicious add- ins in certain directories and tricking a user into starting Visual Studio.
Affected
Microsoft Visual Studio 2008 SP 1 and prior
Microsoft Visual Studio 2010 SP 1 and prior
References
Severity
Classification
-
CVE CVE-2012-0008 -
CVSS Base Score: 6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities
- Microsoft Windows SAMR Protocol Security Bypass Vulnerability (2934418)
- Flaw in SMB Signing Could Enable Group Policy to be Modified (329170)
- Microsoft SharePoint Server Remote Code Execution Vulnerability (2904244)
- Microsoft SharePoint Server HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft .NET Framework Information Disclosure Vulnerability (2567951)