Impact
Deserialization of untrusted data in Microsoft Office SharePoint Server enables an attacker with authorized SharePoint access to run arbitrary code on the server. The flaw is a classic Deserialization of Untrusted Data weakness (CWE‑502) that can compromise confidentiality, integrity, and availability of corporate assets. The vulnerability permits an attacker to take control over the SharePoint service and potentially pivot to other systems in the network (inferred).
Affected Systems
Affected are Microsoft SharePoint Server 2019 and Microsoft SharePoint Server Subscription Edition. No specific version sub‑range is listed; the issue applies to any installation of these products that has not applied the latest Microsoft security update referenced in the official Microsoft Security Update Guide.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of 3% indicates a low but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting that it is not currently actively exploited. Based on the description, it is inferred that a likely attack requires network access to SharePoint and that the attacker already has authorized SharePoint credentials, after which they can supply crafted payloads that trigger unsafe deserialization.
OpenCVE Enrichment