Impact
Improper input validation in Microsoft SharePoint Server permits an attacker to supply crafted network traffic that the system interprets as a valid identity, enabling unauthorized spoofing. This flaw allows the attacker to impersonate a legitimate user or service without valid credentials, potentially granting access to protected resources or functions. The weakness is a classic input validation failure (CWE‑20).
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are impacted. Current releases of these versions may be affected, but no specific sub‑versions or patch levels are identified.
Risk and Exploitability
The CVSS score of 6.5 reflects moderate severity, and the EPSS score of 24% indicates a relatively high probability of exploitation. The vulnerability is listed in the CISA KEV catalog, confirming that it has been used in the wild. Attackers can exploit the flaw remotely by sending crafted input over the network to the SharePoint services without prior credentials or system access, making any network‑exposed SharePoint deployment a high risk.
OpenCVE Enrichment