Microsoft Office SharePoint Server Access Control Flaw Lets Remote Users Gain Administrative Access
|
|
SecurityTracker Alert ID: 1021367 |
|
SecurityTracker URL: http://securitytracker.com/id/1021367
|
|
CVE Reference:
CVE-2008-4032
(Links to External Site)
|
Date: Dec 9 2008
|
Impact:
Denial of service via network, Disclosure of user information, Modification of user information, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): SharePoint Server 2007; SharePoint Server 2007 SP1
|
Description:
A vulnerability was reported in Microsoft Office SharePoint Server. A remote user can gain limited administrative access.
A remote user can directly load certain URLs to bypass authentication and gain access to certain SharePoint administrative functions.
With this access, the remote user can executing commands to cause excessive processing load on the target system. The remote user can also gain access to potentially sensitive information, such as internal path names and users email addresses. The remote user can also create scripts that will execute in the context of the site when other users access the site.
|
Impact:
A remote user can gain limited administrative access on the target application.
|
Solution:
The vendor has issued the following fixes:
Microsoft Office SharePoint Server 2007 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=f8f73997-6f4c-4b43-aa50-5c8276e83d3e
Microsoft Office SharePoint Server 2007 Service Pack 1 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=f8f73997-6f4c-4b43-aa50-5c8276e83d3e
Microsoft Office SharePoint Server 2007 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=a7fda284-273c-42ab-8188-433beaacca86
Microsoft Office SharePoint Server 2007 Service Pack 1 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=a7fda284-273c-42ab-8188-433beaacca86
Microsoft Search Server 2008 (32-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=f8f73997-6f4c-4b43-aa50-5c8276e83d3e
Microsoft Search Server 2008 (64-bit editions):
http://www.microsoft.com/downloads/details.aspx?familyid=a7fda284-273c-42ab-8188-433beaacca86
A restart may be required.
The vendor's advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-077.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms08-077.mspx (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (2003), Windows (2008)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 9 Dec 2008 13:46:07 -0500
Subject: http://www.microsoft.com/technet/security/bulletin/ms08-077.mspx
|
Microsoft Security Bulletin MS08-077 - Important: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175)
CVE-2008-4032
|
|