
====================================================================

                             CERT-Renater

                  Note d'Information No. 2012/VULN273
____________________________________________________________________

DATE                :  11/07/2012

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S):  Systems running
                       Microsoft SharePoint Server version 2010
                       Microsoft Office SharePoint Server version 2007,
                       Microsoft InfoPath version 2007, 2010,
                       Microsoft Groove Server version 2010,
                     Microsoft Windows SharePoint Services version 3.0,
                       Microsoft Office Web Apps version 2010.

======================================================================
KB2695502
http://technet.microsoft.com/en-us/security/bulletin/MS12-050
______________________________________________________________________

Microsoft Security Bulletin MS12-050 - Important Vulnerabilities in
SharePoint Could Allow Elevation of Privilege (2695502)

Published Date: July 10, 2012

Version: 1.0

General Information

Executive Summary

This security update resolves one publicly disclosed and five privately
reported vulnerabilities in Microsoft SharePoint and Windows SharePoint
Services. The most severe vulnerabilities could allow elevation of
privilege if a user clicks a specially crafted URL that takes the user
to a targeted SharePoint site.

This security update is rated Important for supported editions of
Microsoft InfoPath 2007, Microsoft InfoPath 2010, Microsoft SharePoint
Server 2007, Microsoft SharePoint Server 2010, and Microsoft Groove
Server 2010; and for supported versions of Microsoft Windows SharePoint
Services 3.0 and SharePoint Foundation 2010. For more information, see
the subsection, Affected and Non-Affected Software, in this section.

Affected Software

Microsoft InfoPath 2007 Service Pack 2
Microsoft InfoPath 2007 Service Pack 2
Microsoft InfoPath 2007 Service Pack 3
Microsoft InfoPath 2007 Service Pack 3
Microsoft InfoPath 2010 (32-bit editions)
Microsoft InfoPath 2010 (32-bit editions)
Microsoft InfoPath 2010 Service Pack 1 (32-bit editions)
Microsoft InfoPath 2010 Service Pack 1 (32-bit editions)
Microsoft InfoPath 2010 (64-bit editions)
Microsoft InfoPath 2010 (64-bit editions)
Microsoft InfoPath 2010 Service Pack 1 (64-bit editions)
Microsoft InfoPath 2010 Service Pack 1 (64-bit editions)
Microsoft Office SharePoint Server 2007 Service Pack 2 (32-bit editions)
Microsoft Office SharePoint Server 2007 Service Pack 3 (32-bit editions)[1]
Microsoft Office SharePoint Server 2007 Service Pack 2 (64-bit editions)[1]
Microsoft Office SharePoint Server 2007 Service Pack 3 (64-bit editions)[1]
Microsoft SharePoint Server 2010
Microsoft SharePoint Server 2010 Service Pack 1
Microsoft Groove Server 2010
Microsoft Groove Server 2010 Service Pack 1
Microsoft Windows SharePoint Services 3.0 Service Pack 2 (32-bit version)
Microsoft Windows SharePoint Services 3.0 Service Pack 2 (64-bit version)
Microsoft SharePoint Foundation 2010
Microsoft SharePoint Foundation 2010 Service Pack 1
Microsoft Office Web Apps 2010
Microsoft Office Web Apps 2010 Service Pack 1

[1] For supported editions of Microsoft Office SharePoint Server 2007,
in addition to security update packages for Microsoft Office SharePoint
2007 (KB2596663 and KB2596942), customers also need to install the
security update for Microsoft Windows SharePoint Services 3.0
(KB2596911) to be protected from the vulnerabilities described in this
bulletin.

Vulnerability Information

HTML Sanitization Vulnerability - CVE-2012-1858

An information disclosure vulnerability exists in the way that HTML
strings are sanitized. An attacker who successfully exploited this
vulnerability could perform cross-site scripting attacks and run script
in the security context of the logged-on user.

XSS scriptresx.ashx Vulnerability - CVE-2012-1859

A cross-site scripting and elevation of privilege vulnerability exists
in SharePoint allows attacker-controlled JavaScript to run in the
context of the user clicking a link. This is an elevation of privilege
vulnerability as it allows an anonymous attacker to potentially issue
SharePoint commands in the context of an authenticated user on the site.

SharePoint Search Scope Vulnerability - CVE-2012-1860

An information disclosure vulnerability exists in the way that
SharePoint stores search scopes. An attacker could view or tamper with
other users' search scopes.

SharePoint Script in Username Vulnerability - CVE-2012-1861

A cross-site scripting vulnerability exists in SharePoint allows
attacker-controlled JavaScript to run in the context of the user
clicking a link. This is an elevation of privilege vulnerability as it
allows an anonymous attacker to potentially issue SharePoint commands in
the context of an authenticated user.

SharePoint URL Redirection Vulnerability - CVE-2012-1862

A URL redirection vulnerability, which could lead to spoofing and
information disclosure, exists in SharePoint which could allow an
attacker to redirect a user to an external URL.

SharePoint Reflected List Parameter Vulnerability - CVE-2012-1863

A cross-site scripting vulnerability exists in SharePoint allows
attacker-controlled JavaScript to run in the context of the user
clicking a link. This is an elevation of privilege vulnerability as it
allows an anonymous attacker to potentially issue SharePoint commands in
the context of an authenticated user.

======================================================================

=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
=========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44          +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
+ 75013 Paris           | email: certsvp@renater.fr     +
=========================================================
