Impact
The vulnerability is an improper access control flaw that allows an authorized attacker to execute code on a Microsoft SharePoint Server Subscription Edition instance over the network. This weakness, classified as CWE-284, can compromise the confidentiality, integrity, and availability of the affected system by providing the attacker with the ability to run arbitrary code with the permissions of the authenticated user.
Affected Systems
Microsoft SharePoint Server Subscription Edition. No specific version range is listed in the current data.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the risk assessment relies primarily on the CVSS score and the fact that an attacker must be authorized to exploit it. The likely attack vector is a network‑based exploitation that requires valid user credentials, implying that privileged or misconfigured accounts are the main concern. No public exploit evidence is provided, but the high score suggests that once a CVE is disclosed, attackers will likely develop or seek out exploits.
OpenCVE Enrichment