PT-2020-3078 · Microsoft · Skype For Business Server+2
Published
2020-07-14
·
Updated
2026-02-23
·
CVE-2020-1025
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server (affected versions not specified)
Skype for Business Server (affected versions not specified)
Description
An elevation of privilege issue occurs when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. This could allow an attacker to bypass authentication and achieve improper access by modifying the
token.Recommendations
For Microsoft SharePoint Server, update the software to modify how tokens are validated.
For Skype for Business Server, update the software to modify how tokens are validated.
As a temporary workaround, consider restricting access to the OAuth token validation mechanism until a patch is available.
Fix
LPE
Buffer Overflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sharepoint Server
Sharepoint Foundation
Skype For Business Server