This host is missing a important security update according to Microsoft Bulletin MS14-073.
Successful exploitation will allow remote attackers to insert arbitrary HTML and script code, which will be executed in a user's browser session in context of an affected site when the malicious data is being viewed. Impact Level: Application
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, https://technet.microsoft.com/library/security/MS14-073
Certain input related to page content in SharePoint lists is not properly sanitised before being used.
Microsoft SharePoint Foundation 2010 Service Pack 2 and prior.
Get the vulnerable file version and check appropriate patch is applied or not.
- Microsoft DirectShow Elevation of Privileges Vulnerability (2975681)
- Microsoft Office Shared Component Security Bypass Vulnerability (2905238)
- Microsoft ISA Server and Forefront Threat Management Gateway DoS Vulnerability (961759)
- Microsoft SharePoint Foundation Privilege Elevation Vulnerability (3000431)
- Microsoft SharePoint Server Remote Code Execution Vulnerability (2904244)