PT-2021-1896 · Microsoft · Sharepoint Server+1
Cameron Vincent
·
Published
2021-01-12
·
Updated
2024-10-08
·
CVE-2021-1712
CVSS v2.0
8.5
High
| Vector | AV:N/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft SharePoint Server (affected versions not specified)
Microsoft SharePoint Foundation (affected versions not specified)
Microsoft SharePoint Enterprise Server (affected versions not specified)
Description
The issue is related to insecure privilege management in Microsoft SharePoint, allowing a remote attacker to elevate their privileges. This can potentially impact the system.
Recommendations
For Microsoft SharePoint Server, update to a version that includes a fix for the insecure privilege management issue.
For Microsoft SharePoint Foundation, apply configuration changes to restrict privilege elevation until a patch is available.
For Microsoft SharePoint Enterprise Server, consider disabling vulnerable features or modules to minimize the risk of exploitation.
As a temporary workaround, restrict access to sensitive areas of the system to prevent potential abuse of elevated privileges.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharepoint Server
Sharepoint Foundation