Microsoft Sharepoint Malformed Request Code Execution Vulnerability

Strike ID:
E10-62401
CVSS:
7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
False Positive:
f
Variants:
2
Year:
2010

Description

This strike exploits a code execution vulnerability in Microsoft Sharepoint Document Coversion Launcher service. The vulnerability is due to insufficient validation of SOAP requests sent to the service interface. By specially crafting a malicious SOAP request, an unauthenticated attacker could execute arbitrary commands on the server.

CVE

Bid