Impact
Microsoft Office SharePoint contains an improper neutralization of special elements used in an SQL command, allowing a SQL injection that can elevate privileges. The vulnerability is classified as CWE-89 and has a CVSS score of 8.8, indicating a serious impact on confidentiality, integrity, and availability for users with elevated access.
Affected Systems
Vendors and products affected include Microsoft SharePoint Server Subscription Edition. No specific version information has been provided, so all versions of this product are potentially impacted until a patch is applied.
Risk and Exploitability
The risk is high, with a CVSS score of 8.8. EPSS data is not available, so the likelihood of exploitation cannot be precisely quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack vector likely requires an authorized user or an authenticated session, as the description states that an authorized attacker can use the flaw to elevate privileges. Lacking further exploitation details, the best estimate is that an attacker who already has legitimate access could abuse the injection to gain higher privileges.
OpenCVE Enrichment