MS12-070 - Important : Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849) - Ve

Discussion in 'Security Alerts' started by News, Oct 9, 2012.

  1. News

    News Extraordinary Robot
    News Feed

    Joined:
    Jun 27, 2006
    Messages:
    26,205
    Likes Received:
    20
    Severity Rating: Important
    Revision Note: V1.0 (October 9, 2012): Bulletin published.
    Summary: This security update resolves a privately reported vulnerability in Microsoft SQL Server on systems running SQL Server Reporting Services (SSRS). The vulnerability is a cross-site-scripting (XSS) vulnerability that could allow elevation of privilege, enabling an attacker to execute arbitrary commands on the SSRS site in the context of the targeted user. An attacker could exploit this vulnerability by sending a specially crafted link to the user and convincing the user to click the link. An attacker could also host a website that contains a webpage designed to exploit the vulnerability. In addition, compromised websites and websites that accept or host user-provided content or advertisements could contain specially crafted content that could exploit this vulnerability.

    More...
     

Share This Page

Loading...