Microsoft Internet Explorer and Sharepoint contain a flaw that may lead to an unspecified unauthorized information disclosure. This issue is triggered when the 'toStaticHTML()' methodĀ fails to properly sanitise HTML code. This may allow a remote attacker to conduct cross-site scripting attacks.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Private
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability. Check the vendor advisory or solution in the references section.