Spoofing attack in Microsoft products - CVE-2022-21987
Published: February 8, 2022
Vulnerability identifier: #VU60417
CSH Severity: Medium
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-21987
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to incorrect processing of user-supplied data in Microsoft SharePoint Server. A remote authenticated attacker can spoof page content.
Affected software
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
How to mitigate CVE-2022-21987
Install updates from vendor's website.