CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS15-047 | Vulnerabilities in Microsoft SharePoint Server Could Allow Remote Code Execution (3058083) | Microsoft SharePoint | Important | 13-05-2015 |
Technical Information
Brief overview of the risk:
This security update resolves vulnerabilities in Microsoft Office server and productivity software. The vulnerabilities could allow remote code execution if an authenticated attacker sends specially crafted page content to a SharePoint server. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the security context of the W3WP service account on the target SharePoint site.
Detailed Information on the risk:
Remote code execution vulnerabilities exist when SharePoint Server improperly sanitizes specially crafted page content. An authenticated attacker could attempt to exploit these vulnerabilities by sending specially crafted page content to a SharePoint server. The attacker who successfully exploited these vulnerabilities could run arbitrary code in the security context of the W3WP service account on the target SharePoint site. Systems that are running an affected version of SharePoint Server are primarily at risk.
Further information on this exploit is available at : MS15-047
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2013
Affected Software
Microsoft SharePoint Server 2007Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2013