Spoofing attack in Microsoft products - CVE-2023-24950

 

Spoofing attack in Microsoft products - CVE-2023-24950

Published: May 9, 2023 / Updated: May 10, 2023


Vulnerability identifier: #VU75909
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-24950
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect processing of user-supplied within the implementation of the AdRotator WebControl. A remote user can perform NTLM relay attack and obtain credentials of the service account.


Affected software

Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server

How to mitigate CVE-2023-24950

Install updates from vendor's website.


External References

Related Security Bulletins