Impact
The vulnerability stems from improper access control within Microsoft SharePoint, specifically Office SharePoint, allowing a user with existing authorized access to perform spoofing across the network. This flaw is a form of authentication bypass (CWE‑284) that enables an attacker to impersonate other users or services. The report does not describe additional consequences such as phishing or session hijacking, so only the spoofing capability is supported by the provided data.
Affected Systems
Affected installations include Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No specific patch versions are listed in the advisory, so all current deployments of these products are potentially vulnerable until Microsoft releases an update.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact. The EPSS score is reported as less than 1%, implying a low likelihood of exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker must already possess authorized SharePoint access; thus the threat is most relevant to compromised internal accounts or malicious insiders. While the risk remains moderate, the lack of an immediate patch emphasizes the need for monitoring and review of permission scopes.
OpenCVE Enrichment