SharePoint Security Bulletin – Critical
Microsoft Security Bulletin MS13-024 – Critical
Vulnerabilities in SharePoint Could Allow Elevation of Privilege (2780176)
Published: Tuesday, March 12, 2013
Executive Summary
This security update resolves four privately reported vulnerabilities in Microsoft SharePoint and Microsoft SharePoint Foundation. The most severe vulnerabilities could allow elevation of privilege if a user clicks a specially crafted URL that takes the user to a targeted SharePoint site.
This security update is rated Critical for all supported editions of Microsoft SharePoint Server 2010 and rated Important for all supported editions of Microsoft SharePoint Foundation 2010. For more information, see the subsection, Affected and Non-Affected Software, in this section.
The security update addresses the vulnerabilities correcting the way that Microsoft SharePoint Server validates URLs and user input. For more information about the vulnerabilities, see the Frequently Asked Questions (FAQ) subsection for the specific vulnerability entry under the next section, Vulnerability Information.
http://technet.microsoft.com/en-us/security/bulletin/ms13-024