This host is missing an important security update according to Microsoft Bulletin MS14-075.
Successful exploitation will allow remote attackers to conduct spoofing and cross-site scripting attacks. Impact Level: System/Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the given link, https://technet.microsoft.com/library/security/MS14-075
Multiple flaws are due to, - An error when validating a request token. - Certain unspecified input is not properly sanitised before being returned to the user. - Certain input related to redirection tokens is not properly verified before being used to redirect users.
Microsoft Exchange Server 2007 Service Pack 3 and prior Microsoft Exchange Server 2010 Service Pack 3 and prior Microsoft Exchange Server 2013 Service Pack 1 and prior Microsoft Exchange Server 2013 Cumulative Update 6.
Get the vulnerable file version and check appropriate patch is applied or not.
CVE CVE-2014-6319, CVE-2014-6325, CVE-2014-6326, CVE-2014-6336
CVSS Base Score: 5.0
- Microsoft SQL Server Report Manager Cross Site Scripting Vulnerability (2754849)
- Microsoft SharePoint SafeHTML Information Disclosure Vulnerabilities (2412048)
- Microsoft Products HTML Sanitisation Component XSS Vulnerability (2741517)
- Microsoft .NET Framework Chart Control Information Disclosure Vulnerability (2567943)
- Microsoft Windows LSASS Denial of Service Vulnerability (975467)