Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2024-49070

7.4HIGH

Summary

A remote code execution vulnerability exists in Microsoft SharePoint that allows an attacker to run arbitrary code on the server. This vulnerability poses significant security risks, as it can be exploited by sending specially crafted requests to affected SharePoint applications. Exploitation of this flaw may give attackers the ability to gain access to sensitive data or execute malicious actions within the affected environment. Organizations using Microsoft SharePoint are strongly advised to apply the necessary patches and updates to mitigate the risk associated with this vulnerability. For further information and specific remediation steps, please refer to Microsoft's official advisory.

Affected Version(s)

Microsoft SharePoint Enterprise Server 2016 x64-based Systems 16.0.0 < 16.0.5478.1000

Microsoft SharePoint Server 2019 x64-based Systems 16.0.0 < 16.0.10416.20026

Microsoft SharePoint Server Subscription Edition x64-based Systems 16.0.0 < 16.0.17928.20290

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.