Microsoft IIS Server XSS Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists when Microsoft IIS Server fails to properly sanitize a specially crafted request. An attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on behalf of the victim, and inject malicious content in the victim’s browser. For this vulnerability to be exploited, a user must click a specially crafted URL. In an email attack scenario, an attacker could exploit the vulnerability by sending an email message containing the specially crafted URL to the user and by convincing the user to click on the specially crafted URL. In a web-based attack scenario, an attacker would have to host a website that contains a specially crafted URL. In addition, compromised websites and websites that accept or host user-provided content could contain specially crafted content that could exploit this vulnerability. An attacker would have no way to force users to visit a specially crafted website. Instead, an attacker would have to convince users to visit the website, typically by getting them to click a link in an email or instant message that directs them to the affected website by way of a specially crafted URL. The security update addresses the vulnerability by correcting how Microsoft IIS Server sanitizes web requests.
🎯 Affected products27
- Windows 10 Version 1511 for 32-bit Systems
- Windows 10 Version 1511 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for Itanium-Based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for Itanium-Based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
✅ Remediation
KB4012606 (Security Update) KB4013198 (Security Update) KB4013429 (Security Update) KB4012215 (Monthly Rollup) KB4012212 (Security Only) KB4012216 (Monthly Rollup) KB4012213 (Security Only) KB4012373 (Security Update) KB4012217 (Monthly Rollup) KB4012214 (Security Only)
🔗 References (21)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-0055
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012606
- referencehttps://support.microsoft.com/en-us/kb/4012606
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4013198
- referencehttps://support.microsoft.com/en-us/kb/4013198
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4013429
- referencehttps://support.microsoft.com/en-us/kb/4013429
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012215
- referencehttps://support.microsoft.com/en-us/help/4012215
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012212
- referencehttps://support.microsoft.com/en-us/help/4012212
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012216
- referencehttps://support.microsoft.com/en-us/help/4012216
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012213
- referencehttps://support.microsoft.com/en-us/help/4012213
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012373
- referencehttps://support.microsoft.com/en-us/kb/4012373
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012217
- referencehttps://support.microsoft.com/en-us/help/4012217
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4012214
- referencehttps://support.microsoft.com/en-us/help/4012214