PT-2015-5430 · Microsoft · Sharepoint Foundation 2013+5

Published

2015-05-12

·

Updated

2018-10-12

·

CVE-2015-1700

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server 2007 SP3 Microsoft SharePoint Foundation 2010 SP2 Microsoft SharePoint Server 2010 SP2 Microsoft SharePoint Foundation 2013 SP1
Description The issue allows remote authenticated users to execute arbitrary code via crafted page content. This occurs because SharePoint Server improperly sanitizes specially crafted page content, enabling an attacker to run arbitrary code in the security context of the W3WP service account on the target SharePoint site.
Recommendations For Microsoft SharePoint Server 2007 SP3, update to a newer version to mitigate the risk. For Microsoft SharePoint Foundation 2010 SP2, update to a newer version to mitigate the risk. For Microsoft SharePoint Server 2010 SP2, update to a newer version to mitigate the risk. For Microsoft SharePoint Foundation 2013 SP1, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to crafted page content until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-1700

Affected Products

Sharepoint Foundation 2010
Sharepoint Foundation 2013
Sharepoint Server 2007
Sharepoint Server 2010
Sharepoint Foundation
Sharepoint Server