PT-2020-3078 · Microsoft · Skype For Business Server+2

Published

2020-07-14

·

Updated

2026-02-23

·

CVE-2020-1025

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Skype for Business Server (affected versions not specified)
Description An elevation of privilege issue occurs when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. This could allow an attacker to bypass authentication and achieve improper access by modifying the token.
Recommendations For Microsoft SharePoint Server, update the software to modify how tokens are validated. For Skype for Business Server, update the software to modify how tokens are validated. As a temporary workaround, consider restricting access to the OAuth token validation mechanism until a patch is available.

Fix

LPE

Buffer Overflow

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03370
CVE-2020-1025

Affected Products

Sharepoint Server
Sharepoint Foundation
Skype For Business Server