Impact
Microsoft SharePoint Server Subscription Edition suffers a missing authorization flaw that permits an authenticated attacker to remotely execute code. The vulnerability arises from insufficient checks on privileged actions, allowing the attacker to trigger arbitrary code on the server. As a result, compromise grants full process execution control, enabling compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Vulnerable systems are Microsoft SharePoint Server Subscription Edition instances. Specific affected product versions are not enumerated in the data; administrators should verify against the official Microsoft Security Update guide referenced. All installations that have not applied the latest security update are potentially exposed.
Risk and Exploitability
The CVSS score is 8.8, indicating high severity. The EPSS score is not available, so the current exploitation probability remains unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the network from an authenticated user; correct authentication exists but the authorization check is missing. Exploitation requires valid credentials with sufficient privileges but does not require further vulnerabilities.
OpenCVE Enrichment