Impact
The description states that deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. This unsafe deserialization (CWE‑502) provides a means for the attacker to inject or manipulate content, leading to spoofed information presented to users. While CWE‑79 is also listed, the scripting, so that possibility remains inferred rather than confirmed.
Affected Systems
The vulnerability impacts Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. Version information is not specified, so any release prior to the latest security update from Microsoft is potentially affected.
Risk and Exploitability
The description states that deserialization of untrusted data in authorized attacker to perform spoofing over a network. The CVSS score of 5.4 indicates moderate severity. The EPSS score is approximately 0.00937 (<1%), indicating a very low but non‑zero probability of exploitation, and the flaw is not listed in CISA’s KEV catalog, suggesting it is not widely exploited in the wildtrusted data (CWE‑502), and while CWE is listed, the current description does not explicitly mention it. The likely attack vector is web‑based; an attacker must have valid credentials or be able to submit content to the SharePoint instance to trigger the injection. If this condition is met, the attacker can present spoofed content to end users, undermining trust and potentially facilitating further social‑engineering or phishing attacks.
OpenCVE Enrichment