MS15-118 .NET Vulnerabilities "could allow elevation of privilege"


hello,

there's article: https://support.microsoft.com/en-us/kb/3097996  , inside following statement:

this update resolves vulnerabilities in microsoft .net framework. severe of these vulnerabilities allow elevation of privilege if attacker injects client-side script in user's browser. learn more vulnerability, see microsoft security bulletin ms15-118.

understand vulnerability , affecting.

the "elevation of privilege" - elevation of privilege on end-user's os / browser if accesses link site takes advantage of vulnerability ? or elevation of privilege on .net application server has not been patched ?  don't quite understand outcome of vulnerability in case taken advantage of...  if explain grateful.

thanks!

elevation of privilege

every computer program has notion of "privilege" built in, meaning, permission set of actions on system. this permission granted individuals based on ability present proper credentials (for example, username , password).  privilege has levels -- example, guest account typically has fewer privileges administrator account.  many network attacks begin attacker obtaining limited privileges on system, attempting leverage privileges greater privileges might lead controlling system.

[read more here]

so, if user don't have admin rights, system cannot affected easy, don't mean attacker can't control of system. 

hope advice you. 



ninja 4 it



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file