PT-2011-1231 · Microsoft · Windows Server 2008 R2+3

Ruggero Strabla

·

Published

2011-06-16

·

Updated

2020-09-28

·

CVE-2011-1264

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2008 Gold Microsoft Windows Server 2008 SP2 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2008 R2 SP1
Description The issue is related to a cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. The exploitation of this vulnerability can enable a remote attacker to perform cross-site scripting attacks.
Recommendations For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Windows Server 2008 Gold, apply the necessary patch or update to resolve the vulnerability. For Microsoft Windows Server 2008 SP2, install the relevant security update to mitigate the risk. For Microsoft Windows Server 2008 R2, apply the appropriate fix or patch to address the issue. For Microsoft Windows Server 2008 R2 SP1, update to a newer version that includes the resolution for this vulnerability.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04413
CVE-2011-1264

Affected Products

Active Directory Certificate Services Web Enrollment
Windows Server 2003
Windows Server 2008
Windows Server 2008 R2