Microsoft IIS Server XSS CVE-2017-0055 Elevation of Privilege Vulnerability

description-logoDescription

An elevation of privilege vulnerability exists when Microsoft IIS Server fails to properly sanitize a specially crafted request. An attacker who successfully exploited this vulnerability could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. These attacks could allow the attacker to read content that the attacker is not authorized to read, use the victim's identity to take actions on behalf of the victim, and inject malicious content in the victims browser.

affected-products-logoAffected Applications

Windows 10
Windows 7
Windows 8
Windows RT 8.1
Windows Server 2008
Windows Server 2012
Windows Server 2016
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2

CVE References

CVE-2017-0055