Impact
Deserialization of untrusted data in Microsoft SharePoint allows an authorized attacker to execute code on the server over the network. The flaw is a deserialization vulnerability (CWE-502) that can be leveraged to run arbitrary code with the privileges of the SharePoint service. This results in a complete loss of confidentiality, integrity, and availability for the affected SharePoint instance.
Affected Systems
Microsoft SharePoint Server Subscription Edition is affected. No specific version range is provided, so any installation of this product that has not applied the latest Microsoft update is vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score of 1% suggests that exploitation is unlikely but possible. The vulnerability is not listed in CISA KEV, implying no known large-scale exploitation yet. The attack requires network access to the SharePoint service and authentication or a privileged account that can upload or cause parsing of malicious data. Since the flaw involves deserialization, attackers may craft payloads that are interpreted during normal SharePoint processing, resulting in remote code execution.
OpenCVE Enrichment