Oval Definition:oval:org.mitre.oval:def:28924
Revision Date:2015-07-06Version:4
Title:Microsoft SharePoint page content vulnerabilities – CVE-2015-1700 (MS15-047)
Description:Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2015-1700
Platform(s):Microsoft Windows 7
Microsoft Windows 8
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2012 R2
Product(s):Microsoft SharePoint Foundation 2010
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server 2007
Microsoft SharePoint Server 2010
Definition Synopsis
  • Sharepoint 2007 and vulnerable file versions
  • Microsoft Office SharePoint Server 2007 is installed.
  • AND Check if the version of Microsoft.SharePoint.Portal.dll is less than 12.0.6721.5000
  • OR Sharepoint 2010 and vulnerable file version
  • Microsoft Office SharePoint Server 2010 is installed.
  • AND Check if the version of Microsoft.office.policy.dll is less than 14.0.7149.5000
  • OR Sharepoint Foundation 2010 / 2010 SP1
  • Microsoft SharePoint Foundation 2010 is installed
  • AND Check if the version of onetutil.dll is less than 14.0.7149.5000
  • OR Sharepoint Foundation 2013 and vulnerable file version
  • Microsoft SharePoint Foundation 2013 is installed
  • AND Check if the version of stswel.dll is less than 15.0.4719.1002
  • BACK