Impact
This vulnerability is an improper access control flaw (CWE‑284) that allows an attacker with authorized access to the SharePoint environment to execute arbitrary code over the network. The flaw can result in full compromise of the affected SharePoint instance, enabling the attacker to modify or exfiltrate data, gain control over hosted applications, or pivot to other systems on the same network. The impact covers confidentiality, integrity, and availability due to the ability to run code with the privileges of the SharePoint service account.
Affected Systems
Microsoft SharePoint Server Subscription Edition is affected. No specific version information was provided, so all installations of the product that match the CNA listing are potentially vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, classifying it as high severity. EPSS data is not available, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is network‑based access that leverages valid credentials or permissions within the SharePoint environment. The attacker must first be authenticated or otherwise authorized; no exploitation can occur from an unauthenticated attacker alone.
OpenCVE Enrichment