Trend Micro Security

Microsoft .NET Elevation Of Privilege Vulnerability (CVE-2015-6099)

  危険度: : 緊急

  概要

A cross-site scripting (XSS) vulnerability exists in the way that .NET Framework validates the value of a HTTP request. An attacker who successfully exploited this vulnerability could inject a client-side script in the user's browser. The script could spoof content, disclose information, or take any action that the user could take on the affected website. Attempts to exploit this vulnerability would require user interaction. In a web-browsing scenario, an attacker could inject specially crafted JavaScript to the user's browser, which could allow the attacker to modify page content, conduct phishing, or perform actions on behalf of the targeted user.

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1000552