Privilege escalation in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2018-0947
Published: March 13, 2018 / Updated: March 13, 2018
Vulnerability identifier: #VU11011
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0947
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.
The weakness exists due to improper verification of tenant permissions by Microsoft SharePoint Server. A remote attacker can send a specially crafted request to an affected SharePoint server and gain system privileges allowing to read, change permissions, and edit or delete content.
Affected software
Microsoft SharePoint Foundation
Microsoft SharePoint Server
Microsoft Project Server
Microsoft SharePoint Server
Microsoft Project Server
How to mitigate CVE-2018-0947
Install updates from vendor's website.