MS12-070: Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849)

This script is Copyright (C) 2012-2013 Tenable Network Security, Inc.


Synopsis :

A cross-site scripting vulnerability in SQL Server could allow
elevation of privilege.

Description :

The remote host has a version of Microsoft SQL Server installed. This
version of SQL Server is running SQL Server Reporting Services (SRSS),
that is affected by a cross-site scripting (XSS) vulnerability that
could allow elevation of privileges. Successful exploitation could
allow an attacker to execute arbitrary commands on the SSRS site in the
context of the targeted user. An attacker would need to entice a user
to visit a specially crafted link in order to exploit the
vulnerability.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms12-070

Solution :

Microsoft has released a set of patches for SQL Server 2000, 2005,
2008, 2008 R2, and 2012.

Risk factor :

Medium / CVSS Base Score : 4.3
(CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N)
CVSS Temporal Score : 3.6
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 62465 ()

Bugtraq ID: 55783

CVE ID: CVE-2012-2552