First published: Thu Dec 16 2010(Updated: )
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Server | =2007-sp2 | |
Microsoft SharePoint Server | =2007-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3964 is considered a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2010-3964, apply the latest security patches provided by Microsoft for SharePoint Server 2007 SP2.
CVE-2010-3964 affects Microsoft SharePoint Server 2007 SP2 on both x64 and x32 architectures.
CVE-2010-3964 allows attackers to execute arbitrary code on the server through a crafted SOAP request.
The vulnerability is associated with the Document Conversions Launcher Service and Document Conversions Load Balancer Service in SharePoint.