Impact
Improper input validation in Microsoft SharePoint Server permits an attacker to supply crafted network traffic that the system interprets as a valid identity, enabling unauthorized spoofing. This flaw allows the attacker to impersonate a legitimate user or service without valid credentials, potentially granting access to protected resources or functions. The weakness is a classic input validation failure (CWE‑20).
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are impacted. Current releases of these versions may be affected, but no specific sub‑versions or patch levels are identified.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity. The EPSS score of 18% indicates a moderate likelihood of exploitation, and the CVE is listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely by sending crafted network traffic to the SharePoint services without prior credentials, allowing impersonation of legitimate users or services.
OpenCVE Enrichment