Information disclosure in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2020-16941

 

Information disclosure in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2020-16941

Published: October 13, 2020


Vulnerability identifier: #VU47573
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16941
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. A local administrator can access to the specific SharePoint page and gain unauthorized access to sensitive information on the system.


Affected software

Microsoft SharePoint Foundation
Microsoft SharePoint Server

How to mitigate CVE-2020-16941

Install updates from vendor's website.


External References

Related Security Bulletins