Impact
Based on the description, it is inferred that the vulnerability permits an attacker who already has authenticated access to Microsoft SharePoint Server Subscription Edition to execute operations with higher privileges than intended. This elevation of privilege can lead to unauthorized manipulation of data and configuration, potentially compromising the confidentiality, integrity, and availability of all assets stored in the SharePoint environment. The weakness is classified as CWE-250, which addresses improper privilege or access control.
Affected Systems
Microsoft SharePoint Server Subscription Edition is affected. No specific version numbers are listed, indicating that all deployments of this product may be vulnerable until a security update is applied.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability carries a high severity rating. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation evidence. Based on the description, it is inferred that the most likely attack vector requires an attacker to have authorized access to the SharePoint Server; from that position, they can exploit the unnecessary privileges to execute higher‑privilege actions across the network.
OpenCVE Enrichment