Deserialization of Untrusted Data in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2019-1296
Published: September 11, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input passed to the SharePoint API endpoint. A remote attacker can send specially crafted request to the affected API and execute arbitrary code on the system in context of the SharePoint server farm account.
Affected software
Microsoft SharePoint Server