Impact
The vulnerability is a flaw in deserialization of untrusted data in Microsoft Office SharePoint. An authenticated attacker, who can log into SharePoint, can send crafted data that is deserialized by the system and consequently execute arbitrary code on the SharePoint server. The weakness is identified as CWE‑502 and allows the attacker to compromise confidentiality, integrity, and availability of the affected SharePoint installation.
Affected Systems
Microsoft SharePoint Server 2016 Enterprise Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition.\"
Risk and Exploitability
This vulnerability has a CVSS score of 8.8, indicating high severity. The EPSS score is 2%, and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack path requires network access to the SharePoint server and an authenticated session. Based on the description, it is inferred that the attacker must have valid credentials to send the malicious data, after which the server will execute code in its own context.
OpenCVE Enrichment