(MS10-089) Vulnerabilities in Forefront Unified Access Gateway (UAG) Could Allow Elevation of Privilege (2316074)
Publish date: 11 de febrero de 2011
Gravedad: High
Identificadores de CVE : CVE-2010-2733,CVE-2010-2734,CVE-2010-2736
Fecha recomendada: 11 de febrero de 2011
Descripci¨®n
This security update resolves four vulnerabilities in Forefront Unified Access Gateway (UAG). Of the four vulnerabilities, the most critical vulnerability could allow elevation of privilege if users use a specially crafted URL to visit certain websites. These malicious URLs could arrive via spammed messages sent through email or Instant Messaging applications.
Revelaci¨®n de la informaci¨®n
For information on patches specific to the affected software, please proceed to the .
live casino online clients using OfficeScan with Intrusion Defense Firewall (IDF) may refer to the table below for the pattern filter identifier(s):
Vulnerability ID | Identifier & Title | IDF First Pattern Version | IDF First Pattern Release Version |
---|---|---|---|
CVE-2010-2733 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
CVE-2010-2734 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
CVE-2010-2736 | 1000552 - Generic Cross Site Scripting (XSS) Prevention | 10-035 | Nov 10, 2010 |
Soluciones
Parche :
live casino online Deep Security DPI Rule Number: 1000552
live casino online Deep Security DPI Rule Name: Generic Cross Site Scripting (XSS) Prevention
Software y versi¨®n afectados
- Forefront Unified Access Gateway 2010
- Forefront Unified Access Gateway 2010 Update 1
- Forefront Unified Access Gateway 2010 Update 2