PT-2021-6048 · Microsoft · Sharepoint Server+1

Mr_Me

+1

·

Published

2021-07-13

·

Updated

2023-12-28

·

CVE-2021-34468

CVSS v2.0

7.9

High

VectorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Foundation (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified)
Description The issue is related to incorrect code generation management in Microsoft SharePoint products. It allows remote attackers to execute arbitrary code and affect the system. The vulnerability can be exploited to gain unauthorized access and execute malicious code.
Recommendations For Microsoft SharePoint Server, consider restricting access to sensitive areas of the system until a fix is available. For Microsoft SharePoint Foundation, avoid using potentially vulnerable modules or functions that may be related to code generation management. For Microsoft SharePoint Enterprise Server, as a temporary workaround, consider disabling any features that may be related to the vulnerable code generation management. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-00641
BDU:2022-00642
CVE-2021-34468
ZDI-21-829

Affected Products

Sharepoint Server
Sharepoint Foundation