This host is missing an important security update according to Microsoft Bulletin MS14-075.
Successful exploitation will allow remote attackers to conduct spoofing and cross-site scripting attacks. Impact Level: System/Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the given link, https://technet.microsoft.com/library/security/MS14-075
Multiple flaws are due to, - An error when validating a request token. - Certain unspecified input is not properly sanitised before being returned to the user. - Certain input related to redirection tokens is not properly verified before being used to redirect users.
Microsoft Exchange Server 2007 Service Pack 3 and prior Microsoft Exchange Server 2010 Service Pack 3 and prior Microsoft Exchange Server 2013 Service Pack 1 and prior Microsoft Exchange Server 2013 Cumulative Update 6.
Get the vulnerable file version and check appropriate patch is applied or not.
CVE CVE-2014-6319, CVE-2014-6325, CVE-2014-6326, CVE-2014-6336
CVSS Base Score: 5.0
- Microsoft Windows Kernel-Mode Drivers Privilege Elevation Vulnerabilities (2778344)
- Microsoft Window Audio Service Privilege Escalation Vulnerability (3005607)
- Microsoft .NET Framework Denial of Service Vulnerability (2990931)
- Microsoft Windows Local Procedure Call Local Privilege Escalation Vulnerability (2898715)
- Microsoft SharePoint Foundation Privilege Elevation Vulnerability (3000431)