MS15-047: Description of the security update for SharePoint Server 2010: May 12, 2015

Applies to: Microsoft SharePoint Server 2010 Service Pack 2

Summary



This security update resolves vulnerabilities in Microsoft Office server and productivity software. The vulnerabilities could allow remote code execution if an authenticated attacker sends specially crafted page content to a SharePoint server. An attacker who successfully exploited these vulnerabilities could run arbitrary code in the security context of the W3WP service account on the target SharePoint site.


The security update addresses the vulnerabilities by correcting how SharePoint Server sanitizes specially crafted page content. For more information about the vulnerabilities, see the "More Information" section.

Improvements and fixes

This security update also contains fixes for the following nonsecurity issues:
  • Expiration date of a document that is declared as a record is not displayed in SharePoint Server 2010.
  • Translates some terms to multiple languages to make sure of the accuracy of the meaning.

Introduction


Microsoft has released security bulletin MS15-047. To learn more about this security bulletin:

How to obtain help and support for this security update

Help installing updates:
Support for Microsoft Update

Security solutions for IT professionals:
TechNet Security Troubleshooting and Support

Help protect your Windows-based computer from viruses and malware:
Virus Solution and Security Center

Local support according to your country:
International Support

More Information


Note After you install this security update on all SharePoint servers, you have to run the PSconfig tool to complete the installation process. For more information about how to use the PSconfig tool, go to the following Microsoft TechNet webpage:

Restart information

You may have to restart the computer after you install this security update.

In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, a message is displayed that advises you to restart the computer.

To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update.

See Why you may be prompted to restart your computer after you install a security update on a Windows-based computer for more information.

Removal information

You cannot uninstall this security update.

Security update replacement information

This security update replaces security update 2837598 .

FILE INFORMATION


The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.