PT-2019-3360 · Microsoft · Sharepoint Server+1

Markus Wulftange

+1

·

Publicado

2019-09-10

·

Atualizado

2019-09-12

·

CVE-2019-1295

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified) Microsoft SharePoint Foundation (affected versions not specified)
Description A remote code execution issue exists due to insufficient input validation in Microsoft SharePoint. This could allow a remote attacker to execute arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. The issue arises because APIs are not properly protected from unsafe data input.
Recommendations For Microsoft SharePoint Server, update to a version that includes the fix for this issue. For Microsoft SharePoint Enterprise Server, update to a version that includes the fix for this issue. For Microsoft SharePoint Foundation, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to APIs that are not properly protected from unsafe data input until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03490
CVE-2019-1295
ZDI-19-814

Produtos afetados

Sharepoint Server
Sharepoint Foundation