Impact
The vulnerability in Microsoft Office SharePoint allows an attacker who already has authorized credentials to misuse unnecessary privileges and read sensitive information over the network. This represents a privilege escalation flaw (CWE‑250) that results in data disclosure; it does not provide code execution or denial of service.
Affected Systems
The affected product is Microsoft SharePoint Server Subscription Edition. No specific affected version ranges are listed in the advisory, but the issue applies to any installation that exposes SharePoint services to clients.
Risk and Exploitability
The CVSS v3 base score is 6.5, signifying medium severity. The EPSS score is unavailable, so real‑world exploitation probability cannot be determined, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need legitimate access to a SharePoint site and would exploit the privilege misuse path to obtain data via the SharePoint web interfaces or APIs, which can be reached remotely over the network.
OpenCVE Enrichment