Microsoft SharePoint Lets Remote Users Bypass ACP Restrictions on the Target System
|
SecurityTracker Alert ID: 1034653 |
SecurityTracker URL: http://securitytracker.com/id/1034653
|
CVE Reference:
CVE-2015-6117, CVE-2016-0011
(Links to External Site)
|
Date: Jan 12 2016
|
Impact:
Disclosure of user information, Modification of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 2013 SP1
|
Description:
Two vulnerabilities were reported in Microsoft SharePoint. A remote user can bypass security controls on the target system.
The Access Control Policy (ACP) configuration settings are not properly enforced [CVE-2015-6117, CVE-2016-0011]. A remote user can create and add a specially crafted script to a webpart that, when loaded by the target user, will bypass ACP policy to access potentially sensitive information or take actions on the target SharePoint site acting as the target user.
Jonas Nilsson of Disruptive Innovations AB reported one of these vulnerabilities.
|
Impact:
A remote user can bypass ACP security controls on the target system.
|
Solution:
The vendor has issued a fix.
The Microsoft advisory is available at:
https://technet.microsoft.com/library/security/ms16-004
|
Vendor URL: technet.microsoft.com/library/security/ms16-004 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS: Windows (2008), Windows (2012)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|