Impact
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. This flaw, identified as CWE‑502, enables remote code execution on affected SharePoint Server 2016, 2019, and Subscription Edition instances, potentially granting the attacker full control over the underlying host.
Affected Systems
The vulnerability affects Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, and Microsoft SharePoint Server Subscription Edition. No specific version constraints are listed, so all current releases are considered affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of 2% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw permits deserialization of untrusted data over a network; an authorized attacker with access to the SharePoint environment can send malicious input that the server deserializes, leading to remote code execution.
OpenCVE Enrichment