Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2012.0862 Vulnerability in System Center Configuration Manager Could Allow Elevation of Privilege (2741528) 12 September 2012 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Microsoft Systems Management Server 2003 SP 3 Microsoft System Center Configuration Manager 2007 SP 2 Publisher: Microsoft Operating System: Windows XP Windows Server 2003 Windows Vista Windows Server 2008 Windows Server 2008 R2 Windows 7 Impact/Access: Cross-site Scripting -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2012-2536 Original Bulletin: http://technet.microsoft.com/en-us/security/bulletin/MS12-062 - --------------------------BEGIN INCLUDED TEXT-------------------- Microsoft Security Bulletin MS12-062 - Important Vulnerability in System Center Configuration Manager Could Allow Elevation of Privilege (2741528) Published Date: September 11, 2012 | Updated Date: Unspecified Version: 1.0 General Information Executive Summary This security update resolves a privately reported vulnerability in Microsoft System Center Configuration Manager. The vulnerability could allow elevation of privilege if a user visits an affected website by way of a specially crafted URL. An attacker would have no way to force users to visit such a website. Instead, an attacker would have to persuade users to visit the website, typically by getting them to click a link in an email message or Instant Messenger message that takes users to the attacker's website. This security update is rated Important for all supported editions of Microsoft System Center Configuration Manager. Known Issues. None Affected Software Microsoft Systems Management Server 2003 Service Pack 3 Microsoft System Center Configuration Manager 2007 Service Pack 2 Vulnerability Information Reflected XSS Vulnerability - CVE-2012-2536 A cross-site scripting (XSS) vulnerability exists in System Center Configuration Manager where code can be injected back to the user in the resulting page, effectively allowing attacker-controlled code to run in the context of the user clicking the link. - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: http://www.auscert.org.au/render.html?cid=1980 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUE/N1O4yVqjM2NGpAQLeIw/6AoZjHouQuRRUS2EHrCc504qjupS+N2Rf ryWUlGSf9FtO6j5b3TuA+blUzMDI2i/5TmtVsjg7+594OjOYe0jp50n9ikF4rwGI 17fyhbif26CSOcPhWM7aM/cM/9yNa8Ih4VYpVH4htyT+0GDo7ZNLcyHKTUHF+oVD Gqf8yuBPF5CvqNxHEpXQrY0pxDXSV9q5tbSdAeU9qX2LG3LIo0OhH6QESsUxgfxz pDBc6D6lB1PieAodUxjd7ZYuVhTiSkYTMTEvvTLathct5LFBlkbKHbtDosmr+3zt 5Tbw+Pecit+NJR6T99+YW/7paWW3dVuP8tI/MUVPV0iRA5fBgQ3qTgYRC/MJVbFR NjLQcB9dlTDlkAuIo5tA6jilna8ZPgbwmwSSluNWh9fgoTJJ9Eiaz4ljJEMOxDTY 2v2ntbf4EykHQ7OIVDDG6NNi+h34BzrtDGQn/sWqSorIIU/blN4+aBl8MFQ4dslv fB+zvcvTBChNUz0PJz/Itau1zH4zniMTvoxsViAPY68OveUZlIfNs/ue0ctH650s Ds4U9i7lVBXKmt6E7NQbqyI7/DDYh6wYSBwNzPPfFi0VvYS8lOd11SuaLH82KXPb weWFT0RoN2zBJYZ3glPsA6FJbYU7xX/YSmDUruW0FqUqwFYHu3/HzyonJiqnyv7f ayZE76B42cw= =177O -----END PGP SIGNATURE-----