Permissions, Privileges, and Access Controls in Microsoft SharePoint Server and Microsoft SharePoint Foundation - CVE-2020-17089
Published: December 8, 2020
Vulnerability identifier: #VU48841
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2020-17089
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Microsoft SharePoint Server
Microsoft SharePoint Foundation
Microsoft SharePoint Server
Microsoft SharePoint Foundation
Software vendor:
Microsoft
Microsoft
Description
The vulnerability allows a remote authenticated attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Microsoft SharePoint, which leads to security restrictions bypass and privilege escalation.
Remediation
Install updates from vendor's website.