Impact
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. The vulnerability is a classic CWE‑20 flaw and can result in full compromise of the affected SharePoint server, granting the attacker control over the system.
Affected Systems
Affected products include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version ranges are provided in the CNA data; the scope of vulnerable releases cannot be determined from the available information.
Risk and Exploitability
The CVSS score of 8.1 signifies a serious severity. The EPSS score is <1%, indicating a low likelihood of exploitation, but the lack of a KEV listing suggests that active exploitation has not yet been reported. Inferred from the description, the attack vector is remote, requiring network connectivity to the SharePoint servers. Given the high severity and potential for exploitation, the risk to organizations that run these servers remains significant.
OpenCVE Enrichment