Microsoft .NET Elevation Of Privilege Vulnerability (CVE-2015-6099)
Severity: CRITICAL
DESCRIPTION
A cross-site scripting (XSS) vulnerability exists in the way that .NET Framework validates the value of a HTTP request. An attacker who successfully exploited this vulnerability could inject a client-side script in the user's browser. The script could spoof content, disclose information, or take any action that the user could take on the affected website. Attempts to exploit this vulnerability would require user interaction.
In a web-browsing scenario, an attacker could inject specially crafted JavaScript to the user's browser, which could allow the attacker to modify page content, conduct phishing, or perform actions on behalf of the targeted user.
TREND MICRO PROTECTION INFORMATION
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1000552