Vulnerability identifier: #VU11011
Vulnerability risk: Low
CVSSv3.1:
CVE-ID:
CWE-ID:
CWE-264
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Microsoft SharePoint Server
Server applications /
Application servers
Microsoft SharePoint Foundation
Server applications /
Application servers
Vendor: Microsoft
Description
The vulnerability allows a remote authenticated attacker to gain elevated privileges on the target system.
The weakness exists due to improper verification of tenant permissions by Microsoft SharePoint Server. A remote attacker can send a specially crafted request to an affected SharePoint server and gain system privileges allowing to read, change permissions, and edit or delete content.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Microsoft SharePoint Server: 2016
Microsoft SharePoint Foundation: 2013
CPE
External links
http://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0947
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?