Описание
Microsoft SharePoint Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
Successful exploitation of this vulnerability could allow an attacker the ability to gain remote code execution via an in-network attacker calling arbitrary endpoints.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Microsoft SharePoint Server Subscription Edition |
Показывать по
10
Возможность эксплуатации
Publicly Disclosed
No
Exploited
No
Latest Software Release
Exploitation Less Likely
EPSS
Процентиль: 68%
0.01281
Низкий
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 8.8
nvd
около 1 месяца назад
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVSS3: 8.8
github
около 1 месяца назад
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
EPSS
Процентиль: 68%
0.01281
Низкий
8.8 High
CVSS3