MS12-070: Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849)

This script is Copyright (C) 2012-2017 Tenable Network Security, Inc.

Synopsis :

A cross-site scripting vulnerability in SQL Server could allow
elevation of privilege.

Description :

The remote host has a version of Microsoft SQL Server installed. This
version of SQL Server is running SQL Server Reporting Services (SRSS),
that is affected by a cross-site scripting (XSS) vulnerability that
could allow elevation of privileges. Successful exploitation could
allow an attacker to execute arbitrary commands on the SSRS site in
the context of the targeted user. An attacker would need to entice a
user to visit a specially crafted link in order to exploit the

See also :

Solution :

Microsoft has released a set of patches for SQL Server 2000, 2005,
2008, 2008 R2, and 2012.

Risk factor :

Medium / CVSS Base Score : 4.3
CVSS Temporal Score : 3.7
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 62465 ()

Bugtraq ID: 55783

CVE ID: CVE-2012-2552

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now