Impact
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute arbitrary code over a network, potentially compromising the SharePoint server and all hosted data.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are vulnerable. No specific version revisions are listed.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity vulnerability, while the EPSS score is not available, making the current exploitation probability unclear. The flaw requires authorized access, meaning that an insider or compromised account could exploit it. Because it is not listed in the CISA KEV catalog, no known public exploits have been formally reported. The likely attack vector involves an attacker who can upload or execute data that the SharePoint Server processes, triggering the vulnerable deserialization path.
OpenCVE Enrichment