Impact
Deserialization of untrusted data in Microsoft SharePoint Server enables an attacker to execute arbitrary code through the network. The flaw arises from the system deserializing input from an external source without adequate validation, creating a classic deserialization vulnerability that maps directly to CWE-502. If exploited, the attacker could compromise confidentiality, integrity, and availability of the affected SharePoint deployment, potentially gaining full control over the server environment.
Affected Systems
Affected Microsoft SharePoint products include SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition. No specific patch version is listed, so all current releases of these products are potentially vulnerable until the official update is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 9.8, indicating critical severity, with an EPSS score of 5% suggesting a low but non-zero likelihood of exploitation at the moment. It is listed in the CISA KEV catalog, affirming that attacks have already occurred or are imminent. Based on the description, the likely attack vector is over a network where an unauthorized attacker sends crafted serialized data to a vulnerable SharePoint endpoint, triggering code execution.
OpenCVE Enrichment