Skip the navigation
)
News

Microsoft issues work-around, advice for SharePoint zero-day

Disable SharePoint 2007 help, require admins to run IE8, says Microsoft advisory

April 30, 2010 12:31 PM ET

Computerworld - Microsoft Corp. on Thursday urged SharePoint 2007 administrators to protect systems against a recently revealed zero-day vulnerability that could be exploited to steal company secrets.

The bug, which was disclosed Wednesday by the Swiss security consultancy High-Tech Bridge, could be used by attackers to pilfer confidential information from companies' SharePoint servers, which are widely used to power corporate intranets and enable internal collaboration.

"The most likely attack scenario is that an attacker sends a malicious link to a user who is logged into their SharePoint server. If the user clicks the link, the JavaScript created by the attacker and embedded in the link would execute in the context of the user who clicked the link," said a trio of Microsoft security engineers in an entry on the company's "Security Research & Defense" blog late Thursday.

Although the company acknowledged that it was working on a fix, it has not set a ship date for the update.

Instead, Microsoft offered an interim work-around that involved disabling access to SharePoint's help system by running a pair of commands from the command prompt. The commands modify the access control list (ACL), Windows' list of file access permissions.

"It's safe to assume the bug or at least the known [attack] vector, is in that area of the code," said Andrew Storms, director of security operations at nCircle Security.

Additionally, Microsoft recommended that administrators run Internet Explorer 8 (IE8), which includes a cross-site scripting filter that can reduce the exploit risk. Administrators will need to modify IE8's settings, however, to switch on the filter for the Local Intranet security zone of the browser, since it's off by default.

Network administrators can also use group policies to enable the filter in the Local Intranet Zone for all IE8 users, Microsoft added.

Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), cautioned administrators to watch where they click. "If you are an admin on SharePoint server, don't click on any emailed suspicious links to server," Ness said via Twitter yesterday. SharePoint administrators would likely be targeted, since they have broader access to the server's data, and its settings, than an everyday user.

Microsoft doesn't rank vulnerabilities it hasn't patched, but Storms said the threat was minor for the moment. "Pretty low risk at this time, given the user interaction required and the intel required to target the victim," he said in an interview conducted over instant messaging.

Only SharePoint Server 2007 and SharePoint Services 3.0 contain the vulnerability. The newer SharePoint Server 2010 -- which made its release to manufacturing (RTM) milestone earlier this month but won't officially launch until May 12 when it debuts alongside Office 2010 -- is immune to this attack.

The last time Microsoft had to patch SharePoint was in October 2007, when the company issued its MS07-059 security update. "For an app that's supposedly rather popular, I'm surprised more people haven't found more bugs in it, [considering] what's usually stored in SharePoint, such as the company's confidential documents," said Storms.

Microsoft's next regularly scheduled Patch Tuesday is May 11.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@ix.netcom.com.

Read more about Enterprise Web 2.0/Collaboration in Computerworld's Enterprise Web 2.0/Collaboration Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Enterprise Web 2.0/Collaboration White Papers
Activities Streams Base An Integrated Social Layer
The enterprise social software market is exploding thanks to converging trends of consumerization, cloud, and mobile. In this must-read report, "The Forrester Wave:...
Enabling Remote Employees with High Quality Video
In this paper, we analyze the delivery of live and on-demand mobile video content. It focuses on specific ways in which organizations can...
A "YouTube-like" Experience For Employees
Leading research firms are predicting that video is becoming a key component of workplace collaboration. More and more, employees are creating and sharing...
Business Video Empowers Social Media. Raising employee performance.
The wisdom of a company resides in the heads of those directly responsible for the non-routine work of the organization. This, coupled with...
Dynamic Video Collaboration in SharePoint.
Driven by the adoption of social collaboration tools and video applications for employees, today's SharePoint managers are under more pressure than ever before...
All Enterprise Web 2.0/Collaboration White Papers
Enterprise Web 2.0/Collaboration Webcasts
Workday's Mobile Solution for iPad
Stay connected while on the go
As the workforce around the world becomes more mobile, enterprises are enabling their workers to stay informed...
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
All Enterprise Web 2.0/Collaboration Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs