Impact
Deserialization of untrusted data in Microsoft Office SharePoint can allow an authorized attacker to execute arbitrary code over the network. The flaw enables the attacker to inject crafted data during deserialization, which the SharePoint server processes without proper validation, leading to code execution with server privileges.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition are all affected. No specific version constraints are listed by Microsoft, so the vulnerability applies to all current releases of these products. The impact applies to the SharePoint web applications hosted on these servers.
Risk and Exploitability
The CVSS score of 8 indicates a high severity vulnerability, but the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation at the time of analysis. The likely attack vector is network based, requiring an attacker with authorized access to the SharePoint environment to supply the malicious payload. If such an attacker succeeds, they can execute code on the server with the permissions of the SharePoint process, potentially compromising the entire server and any connected applications.
OpenCVE Enrichment