Impact
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. The flaw is a classic Missing Authorization issue (CWE-862), enabling attackers who can authenticate to the SharePoint application to run arbitrary code beyond the intended scope, potentially compromising the entire server or any connected services.
Affected Systems
The vulnerability affects Microsoft SharePoint Server Subscription Edition. No specific version range is provided in the CNA data, implying that all current releases of this product are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score is not available, making it unclear how frequently it is exploited. The vulnerability is not listed in CISA’s KEV catalog, so there is no evidence of widespread exploitation yet. The likely attack vector is network‑based; an attacker must first authenticate to the SharePoint system with sufficient privileges, after which they can trigger arbitrary code execution through the missing authorization control.
OpenCVE Enrichment