PT-2014-1212 · Microsoft · Project Server 2013+15

Published

2014-05-13

·

Updated

2018-10-12

·

CVE-2014-0251

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows SharePoint Services 3.0 SP3 SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1 SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1 Project Server 2010 SP1 and SP2 and 2013 Gold and SP1 Web Applications 2010 SP1 and SP2 Office Web Apps Server 2013 Gold and SP1 SharePoint Server 2013 Client Components SDK SharePoint Designer 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1
Description The issue allows remote authenticated users to execute arbitrary code via crafted page content. Exploitation of this issue enables a remote attacker to run arbitrary code and gain full control over the system. The vulnerability is related to errors that occur when processing specially crafted files. An authenticated attacker who successfully exploits this issue could run arbitrary code in the security context of the W3WP service account.
Recommendations For Microsoft Windows SharePoint Services 3.0 SP3, update to a newer version to mitigate the risk. For SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1, update to a newer version to mitigate the risk. For SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1, update to a newer version to mitigate the risk. For Project Server 2010 SP1 and SP2 and 2013 Gold and SP1, update to a newer version to mitigate the risk. For Web Applications 2010 SP1 and SP2, update to a newer version to mitigate the risk. For Office Web Apps Server 2013 Gold and SP1, update to a newer version to mitigate the risk. For SharePoint Server 2013 Client Components SDK, update to a newer version to mitigate the risk. For SharePoint Designer 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to crafted page content until a patch is available.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00383
BDU:2014-00384
BDU:2014-00385
CVE-2014-0251

Affected Products

Windows Sharepoint Services 3.0
Office Web Apps Server 2013
Project Server 2010
Project Server 2013
Sharepoint Designer 2007
Sharepoint Designer 2010
Sharepoint Designer 2013
Sharepoint Foundation 2010
Sharepoint Foundation 2013
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Server 2013
Sharepoint Server 2013 Client Components Sdk
Sharepoint Foundation
Sharepoint Server
Web Applications 2010