First published: Thu Jun 16 2011(Updated: )
Cross-site scripting (XSS) vulnerability in Active Directory Certificate Services Web Enrollment in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "Active Directory Certificate Services Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =r2 | |
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows 2003 Server | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1264 is classified as a medium severity cross-site scripting (XSS) vulnerability.
The recommended fix for CVE-2011-1264 is to apply the relevant security updates provided by Microsoft.
CVE-2011-1264 affects Microsoft Windows Server 2003 SP2 and Windows Server 2008 in various configurations.
Yes, CVE-2011-1264 can be exploited remotely by attackers to inject arbitrary web scripts.
While applying the security update is the best solution, restricting access to the vulnerable components can serve as a temporary workaround.