Input validation error in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1295

 

Input validation error in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1295

Published: September 11, 2019


Vulnerability identifier: #VU21027
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1295
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input passed to the SharePoint API endpoint. A remote attacker can send specially crafted request to the affected API and execute arbitrary code on the system in context of the SharePoint server farm account.


Affected software

Microsoft SharePoint Foundation
Microsoft SharePoint Server

How to mitigate CVE-2019-1295

Install updates from vendor's website.


External References

Related Security Bulletins