Lucene search

K
kasperskyKaspersky LabKLA10614
HistoryOct 14, 2014 - 12:00 a.m.

KLA10614 Code injection vulnerability in Microsoft ASP.NET MVC

2014-10-1400:00:00
Kaspersky Lab
threats.kaspersky.com
69

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.127 Low

EPSS

Percentile

95.5%

XSS vulnerability was found in ASP.NET MVC. By exploiting this vulnerability malicious users can inject arbitrary script. This vulnerability can be exploited remotely via a specially designed web page.

Original advisories

CVE-2014-4075

Related products

Microsoft-ASP.NET-MVC

CVE list

CVE-2014-4075 warning

KB list

2993937

2990942

2993939

2993928

2994397

2992080

Solution

Install necessary updates from the KB section, that are listed in your Windows Update (Windows Update usually can be accessed from the Control Panel)

Impacts

  • CI

Code injection. Exploitation of vulnerabilities with this impact can lead to changes in target code.

Affected Products

  • Microsoft ASP.NET NVC versions 2.0, 3.0, 4.0, 5.0 and 5.1

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.1 Medium

AI Score

Confidence

High

0.127 Low

EPSS

Percentile

95.5%