Impact
The vulnerability is an improper control of code generation that allows an authorized attacker with legitimate credentials to inject code into a Microsoft SharePoint Server instance and execute it over the network. The injected code could run arbitrary commands on the server, potentially compromising its confidentiality, integrity, and availability. This flaw is a code injection weakness (CWE‑94). Because the attacker must have authenticated access to the SharePoint environment, exploitation requires legitimate credentials and access to the code‑generation surface.
Affected Systems
Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition are all affected. No specific revision numbering is listed, so all current builds of these products may be vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is < 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no widespread confirmed exploitation. The description indicates that an authorized attacker with legitimate credentials can inject code and execute it over the network. Because the flaw is a code injection (CWE‑94), the attacker must reach a code generation point that processes untrusted input. Successful exploitation would allow the attacker to run arbitrary code on the SharePoint server, potentially compromising confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment