Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902324
Kategorie:Windows : Microsoft Bulletins
Titel:Microsoft SharePoint Could Allow Remote Code Execution Vulnerability (2455005)
Zusammenfassung:This host is missing a critical security update according to; Microsoft Bulletin MS10-104
Beschreibung:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS10-104

Vulnerability Insight:
The flaws are due an error in the 'Document Conversions Launcher Service'
when handling specially crafted 'Simple Object Access Protocol (SOAP)'
requests in a SharePoint server environment that is using the Document
Conversions Load Balancer Service.

Vulnerability Impact:
Successful exploitation could allow attackers to execute arbitrary code in
the security context of a guest account.

Affected Software/OS:
Microsoft Office SharePoint Server 2007 Service Pack 2.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: BugTraq ID: 45264
Common Vulnerability Exposure (CVE) ID: CVE-2010-3964
http://www.securityfocus.com/bid/45264
Cert/CC Advisory: TA10-348A
http://www.us-cert.gov/cas/techalerts/TA10-348A.html
http://www.zerodayinitiative.com/advisories/ZDI-10-287/
Microsoft Security Bulletin: MS10-104
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-104
http://osvdb.org/69817
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11737
http://www.securitytracker.com/id?1024886
http://secunia.com/advisories/42631
http://www.vupen.com/english/advisories/2010/3226
CopyrightCopyright (C) 2010 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.