Improper access control in Microsoft products - CVE-2024-43503
Published: October 9, 2024
Vulnerability identifier: #VU98240
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-43503
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft SharePoint. A local user can bypass implemented security restrictions and gain elevated privileges on the system.
Affected software
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
Microsoft SharePoint Enterprise Server
Microsoft SharePoint Server
How to mitigate CVE-2024-43503
Install updates from vendor's website.