Deserialization of Untrusted Data in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1296

 

Deserialization of Untrusted Data in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1296

Published: September 11, 2019


Vulnerability identifier: #VU21030
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-1296
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input passed to the SharePoint API endpoint. A remote attacker can send specially crafted request to the affected API and execute arbitrary code on the system in context of the SharePoint server farm account.


Affected software

Microsoft SharePoint Foundation
Microsoft SharePoint Server

How to mitigate CVE-2019-1296

Install updates from vendor's website.


External References

Related Security Bulletins