Information disclosure in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2020-16942

 

Information disclosure in Microsoft SharePoint Foundation and Microsoft SharePoint Server - CVE-2020-16942

Published: October 13, 2020


Vulnerability identifier: #VU47574
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16942
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. A local administrator can access to the specific SharePoint page and gain unauthorized access to sensitive information on the system.


Affected software

Microsoft SharePoint Foundation
Microsoft SharePoint Server

How to mitigate CVE-2020-16942

Install updates from vendor's website.


External References

Related Security Bulletins