Improper access control in Microsoft products - CVE-2024-43503

 

Improper access control in Microsoft products - CVE-2024-43503

Published: October 9, 2024


Vulnerability identifier: #VU98240
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-43503
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in Microsoft SharePoint. A local user can bypass implemented security restrictions and gain elevated privileges on the system.


Affected software

Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server

How to mitigate CVE-2024-43503

Install updates from vendor's website.


External References

Related Security Bulletins