Impact
An authorized attacker who can send network traffic to a Microsoft Office SharePoint server may exploit unsafe deserialization of untrusted data. This vulnerability can allow the attacker to execute arbitrary code on the SharePoint server. Based on the description, it is inferred that such code execution could enable the attacker to influence the server's confidentiality, integrity, or availability by running code with the privileges of the web service process.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are affected. No specific version exclusions were listed, so all current builds of these products are considered vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of 33% suggests a relatively high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires an authenticated user who can generate network traffic to the SharePoint server. Once executed, the attacker can potentially gain full control of the server.
OpenCVE Enrichment