Privilege escalation in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2018-0947

 

Privilege escalation in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2018-0947

Published: March 13, 2018 / Updated: March 13, 2018


Vulnerability identifier: #VU11011
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0947
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.

The weakness exists due to improper verification of tenant permissions by Microsoft SharePoint Server. A remote attacker can send a specially crafted request to an affected SharePoint server and gain system privileges allowing to read, change permissions, and edit or delete content.


Affected software

Microsoft SharePoint Foundation
Microsoft SharePoint Server
Microsoft Project Server

How to mitigate CVE-2018-0947

Install updates from vendor's website.


External References

Related Security Bulletins