Microsoft Sharepoint Server Remote Code Execution Vulnerability

Microsoft Sharepoint Server Remote Code Execution Vulnerability

Microsoft has announced a new remote code execution vulnerability that affects SharePoint server.

Microsoft Sharepoint Server Remote Code Execution Vulnerability

Successfull exploitation can lead to remote code execution.

Affected Systems

  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Enterprise Server 2013 Service Pack 1
  • Microsoft SharePoint Enterprise Server 2016

IOC’s

-

Recommended Solution(s)

Organizations using the above-mentioned products are recommended apply applicable patches mentioned in https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41038 .

CVE / CWE

CVE-2022-41038

Related Website

* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.