This update resolves vulnerabilities that could allow elevation of privilege if an attacker sends a specially crafted request to an affected Microsoft Project Server 2010. The attacker who successfully exploited these vulnerabilities could then perform cross-site scripting attacks on affected systems and run script in the security context of the current user. An attacker who successfully exploited the vulnerabilities could read content that the attacker is not authorized to read, use the victim's identity to take actions on behalf of the victim, such as change permissions, delete content, and insert malicious content in the victim’s browser.
Microsoft has released security bulletin MS15-036. Learn more about how to obtain the fixes that are included in this security bulletin:
- Individual, small business, and organizational users should use the Windows automatic updating feature to install the fixes from Microsoft Update. To do this, see Get security updates automatically on the Microsoft Safety and Security Center website.
- For IT professionals, see Microsoft Security Bulletin MS15-036 on the Security TechCenter website.
How to obtain help and support for this security updateHelp installing updates: Support for Microsoft Update
Security solutions for IT professionals: TechNet Security Troubleshooting and Support
Help protect your computer that is running Windows from viruses and malware: Virus Solution and Security Center
Local support according to your country: International Support
Restart informationYou may have to restart the computer after you install this security update.
In some cases, this update does not require a restart. If the required files are being used, this update will require a restart. If this behavior occurs, you will receive a message that advises you to restart the computer.
To help reduce the possibility that a restart will be required, stop all affected services and close all applications that may use the affected files before you install this security update.
Learn about why you may be prompted to restart your computer after you install a security update on a Windows-based computer.