Impact
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. The vulnerability is a classic instance of unsafe deserialization (CWE-502) and results in arbitrary code execution, which can compromise confidentiality, integrity, and availability of the affected SharePoint installation.
Affected Systems
The flaw affects Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version ranges are provided by the CNA, so all current releases of these products are considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of 1% indicates a low exploitation probability, and the vulnerability is not listed in CISA KEV. The attack likely requires an attacker who has authenticated access to the SharePoint environment to send malicious serialized data to a component that performs deserialization over the network. Given the high severity and the nature of the flaw, the risk remains substantial until remediation is completed.
OpenCVE Enrichment