Impact
Deserialization of untrusted data in Microsoft SharePoint allows an attacker who can authenticate to the system to execute arbitrary code. Based on the description, it is inferred that successful exploitation would grant the attacker the same privileges as the user who supplied the data, potentially leading to full compromise of the SharePoint server.
Affected Systems
Affected products are Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Version details are not specified in the CVE entry, so the flaw applies to the mentioned releases at all patch levels unless otherwise corrected by a vendor update.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity, and an EPSS score of 3%, reflecting a low but non‑negligible likelihood of exploitation. It is now listed in the CISA KEV catalog. The likely attack vector is an authenticated user who can supply data that the server deserializes; an attacker requires legitimate SharePoint access but not elevated privileges to begin exploitation.
OpenCVE Enrichment