Impact
The vulnerability stems from improper access control within Microsoft SharePoint, allowing an authorized attacker to execute code over the network. This flaw enables a malicious user who already has legitimate access to the system to run arbitrary code, potentially compromising the confidentiality, integrity, and availability of the SharePoint environment.
Affected Systems
Microsoft SharePoint Server Subscription Edition is the sole documented product impacted. No specific version information is supplied in the available data, so any installation of this product should be considered at risk if unpatched.
Risk and Exploitability
The vulnerability scores 8.8 on the CVSS scale, indicating a high severity condition. The EPSS score is not available, and it is currently not listed in the CISA KEV catalog. Attackers would need network access to the SharePoint server and must possess authorized credentials to trigger the payload. Given the lack of publicly disclosed exploits, the likelihood of immediate exploitation may be moderate, but the potential impact warrants prompt action.
OpenCVE Enrichment