CVE-2010-3964: High severity microsoft sharepoint server 2010 vulnerability
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3964?
CVE-2010-3964 is considered a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2010-3964?
To fix CVE-2010-3964, apply the latest security patches provided by Microsoft for SharePoint Server 2007 SP2.
What systems are affected by CVE-2010-3964?
CVE-2010-3964 affects Microsoft SharePoint Server 2007 SP2 on both x64 and x32 architectures.
What type of attack is possible with CVE-2010-3964?
CVE-2010-3964 allows attackers to execute arbitrary code on the server through a crafted SOAP request.
What services need to be reviewed due to CVE-2010-3964?
The vulnerability is associated with the Document Conversions Launcher Service and Document Conversions Load Balancer Service in SharePoint.