PT-2014-1212 · Microsoft · Project Server 2013+15
Published
2014-05-13
·
Updated
2018-10-12
·
CVE-2014-0251
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows SharePoint Services 3.0 SP3
SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1
SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1
Project Server 2010 SP1 and SP2 and 2013 Gold and SP1
Web Applications 2010 SP1 and SP2
Office Web Apps Server 2013 Gold and SP1
SharePoint Server 2013 Client Components SDK
SharePoint Designer 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1
Description
The issue allows remote authenticated users to execute arbitrary code via crafted page content. Exploitation of this issue enables a remote attacker to run arbitrary code and gain full control over the system. The vulnerability is related to errors that occur when processing specially crafted files. An authenticated attacker who successfully exploits this issue could run arbitrary code in the security context of the W3WP service account.
Recommendations
For Microsoft Windows SharePoint Services 3.0 SP3, update to a newer version to mitigate the risk.
For SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1, update to a newer version to mitigate the risk.
For SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1, update to a newer version to mitigate the risk.
For Project Server 2010 SP1 and SP2 and 2013 Gold and SP1, update to a newer version to mitigate the risk.
For Web Applications 2010 SP1 and SP2, update to a newer version to mitigate the risk.
For Office Web Apps Server 2013 Gold and SP1, update to a newer version to mitigate the risk.
For SharePoint Server 2013 Client Components SDK, update to a newer version to mitigate the risk.
For SharePoint Designer 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting access to crafted page content until a patch is available.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Sharepoint Services 3.0
Office Web Apps Server 2013
Project Server 2010
Project Server 2013
Sharepoint Designer 2007
Sharepoint Designer 2010
Sharepoint Designer 2013
Sharepoint Foundation 2010
Sharepoint Foundation 2013
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Server 2013 Client Components Sdk
Sharepoint Foundation
Sharepoint Server
Web Applications 2010