Microsoft Content Management Server Remote Code Execution Vulnerability
BID:22861
Info
Microsoft Content Management Server Remote Code Execution Vulnerability
| Bugtraq ID: | 22861 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0938 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 10 2007 12:00AM |
| Updated: | Jun 13 2007 08:29PM |
| Credit: | This issue was disclosed in the referenced vendor advisory. |
| Vulnerable: |
Microsoft Content Management Server 2002 SP2 Microsoft Content Management Server 2002 SP1 Microsoft Content Management Server 2002 Microsoft Content Management Server 2001 SP1 Microsoft Content Management Server 2001 HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Content Management Server Remote Code Execution Vulnerability
Microsoft Content Management Server (MCMS) is prone to an arbitrary code-execution vulnerability because the software fails to properly validate user-supplied input.
Exploiting this issue allows remote attackers to execute arbitrary machine code on affected computers with the privileges of the vulnerable application.
Microsoft Content Management Server (MCMS) is prone to an arbitrary code-execution vulnerability because the software fails to properly validate user-supplied input.
Exploiting this issue allows remote attackers to execute arbitrary machine code on affected computers with the privileges of the vulnerable application.
Exploit / POC
Microsoft Content Management Server Remote Code Execution Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
Microsoft Content Management Server Remote Code Execution Vulnerability
Solution:
Microsoft has released an advisory along with fixes to address this issue in supported versions of affected applications.
HP Storage Management Appliance is affected by the issue; please see the referenced HP advisory.
Microsoft Content Management Server 2001 SP1
Microsoft Content Management Server 2002 SP2
Solution:
Microsoft has released an advisory along with fixes to address this issue in supported versions of affected applications.
HP Storage Management Appliance is affected by the issue; please see the referenced HP advisory.
Microsoft Content Management Server 2001 SP1
-
Microsoft Security Update for Microsoft Content Management Server 2001 (KB924430)
http://www.microsoft.com/downloads/details.aspx?familyid=0AAC923D-A6B8 -4023-9977-AEA6782DC1C7&displaylang=en
Microsoft Content Management Server 2002 SP2
-
Microsoft Security Update for Microsoft Content Management Server 2002 (KB924429)
http://www.microsoft.com/downloads/details.aspx?familyid=41D53931-BCF8 -43D9-9D16-592EBFB0AC04&displaylang=en
References
Microsoft Content Management Server Remote Code Execution Vulnerability
References:
References: