This host is missing a important security update according to Microsoft Bulletin MS14-073.
Successful exploitation will allow remote attackers to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed. Impact Level: Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, https://technet.microsoft.com/library/security/MS14-073
Certain input related to page content in SharePoint lists is not properly sanitised before being used.
Microsoft SharePoint Foundation 2010 Service Pack 2 and prior.
Get the vulnerable file version and check appropriate patch is applied or not.
- Microsoft SharePoint Business Productivity Server RCE Vulnerability (2904244)
- Microsoft Visual Studio Privilege Elevation Vulnerability (2651019)
- Microsoft Outlook Information Disclosure Vulnerability (2894514)
- IE VBScript Handling patch (Q318089)
- Microsoft Host Integration Server Denial of Service Vulnerabilities (2607670)