Deserialization of Untrusted Data in Microsoft products - CVE-2024-43466
Published: September 10, 2024 / Updated: September 11, 2024
Microsoft SharePoint Server
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insecure input validation when processing serialized data within the SPAutoSerializingObject class in Microsoft SharePoint Server. A remote user can pass specially crafted data to the application and cause a denial of service condition on the target system.