#VU22696 Spoofing attack in Microsoft SharePoint Server - CVE-2019-1442
Published: November 12, 2019
Microsoft SharePoint Server
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of certain URLs. A remote attacker can create a specially crafted file, force the victim into opening it and then trick a victim into entering credentials that can be obtained by the attacker.
Successful exploitation of the vulnerability may allow to conduct a phishing attack.