Security features bypass in Microsoft products - CVE-2023-21743
Published: January 10, 2023
Vulnerability identifier: #VU70959
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21743
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to security features bypass in Microsoft SharePoint Server. A remote attacker can bypass authentication and make an anonymous connection.
Affected software
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
How to mitigate CVE-2023-21743
Install updates from vendor's website.