Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-33142

Опубликовано: 13 июн. 2023
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Microsoft SharePoint Server Elevation of Privilege Vulnerability

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability?

An attacker who successfully exploited the vulnerability would be able to create a list or document library in the targeted SharePoint site.

According to the CVSS metrics, successful exploitation of this vulnerability could lead to a major loss of integrity (I:H) but no loss of confidentiality (C:N), or have any effect on availability (A:N). How could an attacker affect the SharePoint site?

An attacker who successfully exploited this vulnerability could create a list or document library in the targeted SharePoint site thus affecting the integrity. However, an attacker could not edit or delete a list or document library from the SharePoint site.

I am running SharePoint Server 2019 and there are multiple updates available. Do I need to install all the updates listed in the Security Updates table for these versions?

Yes. Customers should apply all updates offered for the software installed on their systems. If multiple updates apply, they can be installed in any order.

Обновления

ПродуктСтатьяОбновление
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 80%
0.0145
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
больше 2 лет назад

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVSS3: 6.5
github
больше 2 лет назад

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVSS3: 6.5
fstec
больше 2 лет назад

Уязвимость пакетов программ Microsoft SharePoint Server, Microsoft SharePoint Server Subscription Edition, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 80%
0.0145
Низкий

6.5 Medium

CVSS3