Impact
The vulnerability arises from weak authentication logic in Microsoft SharePoint that permits an attacker without valid credentials to bypass a built‑in security feature over a network. This flaw is classified as CWE‑1390 and can lead to unauthorized access or privilege escalation, potentially compromising the confidentiality, integrity, or availability of protected data or system functions.
Affected Systems
Affected products include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and the SharePoint Server Subscription Edition. All current releases of these as the CVE does not list specific version numbers.
Risk and Exploitability
The EPSS score of 51% indicates a moderate to high probability that the vulnerability will be exploited in the wild, and the vulnerability is listed in the CISA KEV catalog. The attack requires network connectivity to the SharePoint server and the ability to craft authentication requests that exploit the weak validation logic; no local user privileges are needed. With a CVSS score of 9.1, the potential impact is severe, encompassing full unauthorized access and possible system compromise.
OpenCVE Enrichment