ID:4826 - Exploit for Input validation error in Microsoft SharePoint Server - CVE-2020-1444
Published: November 11, 2020
Microsoft SharePoint Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input when the Microsoft SharePoint software improperly parses specially crafted email messages. A remote attacker can send a specially crafted email, then convince the recipient to perform multiple actions while replying to the message and execute arbitrary code on the target system.