Update Protection against Microsoft Office SharePoint Server Access Control Elevation of Privilege (MS08-077)
| Check Point Reference: | CPAI-2008-181 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS08-077 | |
| Industry Reference(s): | CVE-2008-4032 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Office SharePoint Server 2007 (32-bit editions) Microsoft Office SharePoint Server 2007 SP1 (32-bit editions) Microsoft Office SharePoint Server 2007 (64-bit editions) Microsoft Office SharePoint Server 2007 SP1 (64-bit editions) | ||
| Vulnerability Description An elevation of privilege vulnerability was reported in Microsoft Office SharePoint Server 2007. Windows SharePoint Services provide a platform for collaboration applications and document management. Office SharePoint Server is an integrated suite of server capabilities built on top of Windows SharePoint Services. Successful exploitation of this vulnerability could result in elevation of privilege within the SharePoint Site. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-077 |
|
|
Vulnerability Details The vulnerability is due to an error in Microsoft Office SharePoint Server that incorrectly handles access control on a subset of administrative functions. A remote attacker may convince a user to browse to a SharePoint URL, bypassing authentication to a subset of administrative functions. Successful exploitation of this issue may result in information disclosure, and may allow the attacker to cause denial of service by executing commands that would cause load on the server. |
Protection Overview
By enabling this protection, SmartDefense will detect and block attempts to exploit this vulnerability via malicious URLs. IPS-1 will detect and block attempts to access Sharepoint administrative pages without correct credentials.
In order for the protection to be activated, update your VPN-1 product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.