Microsoft .NET Elevation Of Privilege Vulnerability (CVE-2015-6099)
Publish Date: 13 de июля de 2016
Severity: : Critical
DESCRIPTION
A cross-site scripting (XSS) vulnerability exists in the way that .NET Framework validates the value of a HTTP request. An attacker who successfully exploited this vulnerability could inject a client-side script in the user's browser. The script could spoof content, disclose information, or take any action that the user could take on the affected website. Attempts to exploit this vulnerability would require user interaction.
In a web-browsing scenario, an attacker could inject specially crafted JavaScript to the user's browser, which could allow the attacker to modify page content, conduct phishing, or perform actions on behalf of the targeted user.
INFORMATION EXPOSURE
Apply associated Trend Micro DPI Rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1000552