Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-56164

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 5.3
EPSS Средний

Описание

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Меры по смягчению последствий

The following mitigating factors might be helpful in your situation:

Enable AMSI: Ensure the Antimalware Scan Interface (AMSI) is actively integrated and scanning SharePoint and IIS worker process memory. Enable AMSI scan feature and set the Request Body Scan mode to Full in order for POST body payloads to be detected.

Configure AMSI integration with SharePoint Server - https://learn.microsoft.com/en-us/sharepoint/security-for-sharepoint-server/configure-amsi-integration

FAQ

According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?

The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.

I am running SharePoint Server 2016. Do the updates for SharePoint Enterprise Server 2016 also apply to the version I am running?

Yes. The same KB number applies to both SharePoint Server 2016 and SharePoint Enterprise Server 2016. Customers running either version should install the security update to be protected from this vulnerability.

Обновления

ПродуктСтатьяОбновление
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

Yes

Latest Software Release

Exploitation Detected

EPSS

Процентиль: 97%
0.20127
Средний

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
16 дней назад

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
github
16 дней назад

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CVSS3: 5.3
fstec
17 дней назад

Уязвимость пакетов программ Microsoft SharePoint Server, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Enterprise Server, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 97%
0.20127
Средний

5.3 Medium

CVSS3