Impact
The vulnerability is a missing authentication check in a critical function of Microsoft SharePoint Server. This flaw allows an attacker who is already authenticated to the network to gain higher privileges within SharePoint, effectively elevating their access level without proper authorization. The flaw does not provide arbitrary code execution but compromises confidentiality, integrity, and availability by enabling unauthorized users to perform privileged operations.
Affected Systems
The vulnerability affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version numbers are listed, indicating that all current releases of these products are potentially impacted.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that there is no known widespread exploitation at the time of analysis. However, because the flaw permits privileged escalation over an internal network, the likely attack vector is local or within the organization’s trusted network, and an attacker only needs to be authenticated to the network to exploit it.
OpenCVE Enrichment