Impact
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. The vulnerability is a typical CWE‑20 flaw and can lead to full compromise of the affected SharePoint server, giving the attacker control over the system and the ability to exfiltrate data or pivot to other assets.
Affected Systems
Affected products include Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version ranges are provided in the CNA data; all releases of these products are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.1 signifies a serious severity. The EPSS score is 3%, indicating a moderate likelihood of exploitation, but the lack of a KEV listing suggests that active exploitation has not yet been reported. Inferred from the description, the attack vector is remote, requiring network connectivity to the SharePoint servers. Given the high severity and potential for exploitation, the risk to organizations that run these servers remains significant.
OpenCVE Enrichment