19 October 2020

UK NCSC urges orgs to patch dangerous Microsoft SharePoint RCE flaw


UK NCSC urges orgs to patch dangerous Microsoft SharePoint RCE flaw

The U.K. National Cyber Security Centre (NCSC) has released an alert highlighting the dangers of the CVE-2020-16952 remote code execution vulnerability affecting Microsoft SharePoint Server, which has been addressed by Microsoft with the October Patch Tuesday release. The cybersecurity agency has urged organizations to immediately patch the vulnerability.

If exploited, CVE-2020-16952 could allow an attacker to run arbitrary code in the context of the local administrator on affected installations of SharePoint server. The vulnerability exists due to a validation issue in user-supplied data and can be exploited when a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.

The issue affects the following SharePoint releases:

  • Microsoft SharePoint Foundation 2013 Service Pack 1

  • Microsoft SharePoint Enterprise Server 2016

  • Microsoft SharePoint Server 2019

SharePoint Online as part of Office 365 is not impacted.

"The NCSC strongly advises that organizations refer to the Microsoft guidance referenced in this alert and ensure the necessary updates are installed in affected SharePoint products. The NCSC generally recommends following vendor best practice advice in the mitigation of vulnerabilities. In the case of this SharePoint vulnerability, it is important to install the latest updates as soon as practicable," the alert said.

Since SharePoint servers are used in enterprise environments such a flaw can pose a significant risk to organizations. Although there are no reports about the CVE-2020-16952 being exploited in real-world attacks, chances of this happening are high given that a proof-of-concept exploit demonstrating how remote code execution can be achieved is already available.


Back to the list

Latest Posts

Cyber Security Week in Review: May 10, 2024

Cyber Security Week in Review: May 10, 2024

In brief: Google fixes yet another Chrome 0Day, Dell suffers a data breach, the LockBit leader identified, and more.
10 May 2024
Massive BogusBazaar fraud ring steals credit cards from thousands of victims

Massive BogusBazaar fraud ring steals credit cards from thousands of victims

As of April 2024, approximately 22,500 domains were active.
9 May 2024
Poland’s government institutions targeted in Russian cyberespionage campaign

Poland’s government institutions targeted in Russian cyberespionage campaign

The incident marks the latest in a string of Russian cyberattacks aimed at NATO-allied nations supporting Ukraine.
9 May 2024