Buffer overflow in Microsoft products - CVE-2020-1025
Published: July 14, 2020 / Updated: July 15, 2020
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. A local user can modify the token, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Microsoft SharePoint Server
Skype for Business Server