Impact
The vulnerability is a server‑side request forgery that allows an attacker with legitimate access to the SharePoint Server to elevate their privileges by manipulating outbound requests. The flaw can lead to unauthorized access to internal resources or the acquisition of higher‑level permissions within the SharePoint environment. This is a high‑severity flaw (CVSS score 8.8).
Affected Systems
Microsoft SharePoint Server Subscription Edition is impacted. No specific affected versions are listed in the CVE data, so the risk applies to all deployments of this product until a patch is applied.
Risk and Exploitability
The EPSS score is reported as less than 1%, indicating that, as of now, the probability of exploitation is low and no known exploits have been observed. The flaw is not currently catalogued in the CISA Known Exploit Vulnerability catalog. The likely attack vector requires an authorized user to send a crafted request that exploits the server’s outbound request capability, leading to privilege escalation over the internal network. The CVSS score underscores the seriousness of successful exploitation, but the low EPSS suggests opportunistic attackers may deprioritise this vulnerability.
OpenCVE Enrichment