Remote Code Execution Vulnerability in Microsoft SharePoint
CVE-2020-0931

8.8HIGH

Summary

A remote code execution vulnerability in Microsoft SharePoint arises when the application does not correctly validate the source markup of application packages. An attacker could exploit this flaw to execute arbitrary code on the server. This could potentially allow the attacker to gain control over the SharePoint environment, exposing sensitive data and compromising system integrity.

Affected Version(s)

Microsoft Business Productivity Servers 2010 Service Pack 2

Microsoft SharePoint Enterprise Server 2013 Service Pack 1

Microsoft SharePoint Enterprise Server 2016

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.