This host is missing an important security update according to Microsoft Bulletin MS14-059.
Successful exploitation will allow attacker to execute arbitrary HTML and script code in a user's browser session in the context of an affected site. Impact Level: System/Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the link, https://technet.microsoft.com/en-us/security/bulletin/ms14-059
Certain unspecified input is not properly sanitised in System.Web.Mvc.dll before being returned to the user.
ASP.NET MVC 2.0/3.0/4.0/5.0/5.1
Get the vulnerable file version and check appropriate patch is applied or not.
- Microsoft InfoPath HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft Windows Media Service Handshake Sequence DoS Vulnerability
- Microsoft Windows DirectWrite Denial of Service Vulnerability (2665364)
- Microsoft Windows Kernel Privilege Elevation Vulnerabilities (2813170)
- Microsoft .NET Framework Remote Code Execution Vulnerability (2538814)