Elevation of Privilege Vulnerability in Microsoft SharePoint Server
CVE-2018-8254

5.4MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
14 June 2018

Summary

An elevation of privilege vulnerability is present in Microsoft SharePoint Server due to improper sanitization of specially crafted web requests. This flaw enables attackers to exploit the vulnerable SharePoint server, potentially allowing them to execute arbitrary actions with elevated privileges. Organizations using affected versions of Microsoft SharePoint Server and Microsoft Project Server must ensure proper security measures are in place to mitigate this risk. For detailed security guidance, consult the official advisory linked below.

Affected Version(s)

Microsoft Project Server 2010 Service Pack 2

Microsoft SharePoint Enterprise Server 2016

Microsoft SharePoint Foundation 2013 Service Pack 1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.