Microsoft warns of serious SharePoint cross-site scripting zero-day

Article

Microsoft warns of serious SharePoint cross-site scripting zero-day

Robert Westervelt, News Editor

Microsoft issued a security advisory late Thursday, warning SharePoint users of a new SharePoint zero-day vulnerability that could allow elevation of privilege.

Jerry Bryant, Microsoft's group manager of response communications, said the software giant was unaware of any active attacks attempting to exploit the flaw. The cross-site scripting (XSS) vulnerability affects SharePoint Server 2007 and SharePoint Services 3.0. The vulnerability can be exploited in a browser-based attack.

The Microsoft advisory includes a workaround to mitigate against the threat. Microsoft said users can restrict access by adding an access control list to SharePoint Help.aspx XML files. The workaround will, however, disable all help functionality from the SharePoint server, Microsoft said.

Servers are at reduced risk from Internet Explorer 8 clients, Microsoft said. IE 8 includes an XSS filter in the Internet zone that can block an attack.

According to an advisory issued by High-Tech Bridge SA, a security firm based in Switzerland, the SharePoint vulnerability could enable an attacker to execute JavaScript code within the vulnerable application. The firm said that it notified Microsoft of the vulnerability on April 12.

"Successful exploitation of this vulnerability could result in a compromise of the application,

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

theft of cookie-based authentication credentials, disclosure or modification of sensitive data," the firm warned.

Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.