Impact
Deserialization of untrusted data in Microsoft SharePoint Server allows an attacker who is already authorized on the system to execute arbitrary code over the network. The vulnerability is classified as a high severity Remote Code Execution flaw with a CVSS score of 8.8. The weakness, identified as CWE‑502, means that the service blindly processes input that can be crafted to inject malicious content, thereby giving the attacker the ability to take control of the SharePoint host and potentially compromise the confidentiality, integrity, and availability of that server.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition are all affected. No specific patch level or sub‑version is listed, so any installation of these products is potentially vulnerable until a vendor‑issued update is applied.
Risk and Exploitability
The threat remains high because the vulnerability can be triggered by a network request from an attacker who possesses valid SharePoint credentials. The EPSS score of 1% indicates a very low but non‑zero probability of exploitation, while the CVSS score denotes a serious impact, and the vulnerability is not listed in CISA’s KEV catalog. An attacker could use the flaw to compromise the SharePoint environment, exfiltrate data, install malware, or pivot to other systems. Because the exploit requires prior authorization, internal attackers or compromised user accounts are the most likely threat actors.
OpenCVE Enrichment