Impact
A time‑of‑check time‑of‑use race condition in Microsoft Office SharePoint allows an authorized attacker to execute arbitrary code over the network. The flaw is a classic CWE‑367 scenario, where a file is inspected for safe use but the state changes before the file is used, enabling malicious activity
Affected Systems
Microsoft SharePoint Server Subscription Edition
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, and the vulnerability is not listed in CISA KEV. Although an EPSS score is not available, the lack of a public exploit does not reduce the risk. The flaw can be triggered over a network by an attacker who has legitimate SharePoint access. An authenticated compromise could lead to arbitrary code execution with the permissions of the SharePoint process.
OpenCVE Enrichment