Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sharepoint_server | 16.0.0, 16.0.0, 16.0.0 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| microsoft | microsoft sharepoint server subscription edition | mitre_affected | 90% |
| microsoft | microsoft sharepoint | mitre_affected | 90% |
Updated affected versions, added new CWEs, and included new tags related to missing authentication and deserialization.
Added CWE-20 and updated tags to include 'remote code execution'.
Added affected versions including Subscription Edition, 2019, and 2016, and new CWE and tags related to zero-day and privilege escalation.
Updated description with new technical details, added affected version, and specified the fixed version number.
Updated description with new details, changed product to 'Microsoft SharePoint Server', severity to 'HIGH', and noted no exploit available.
Updated description with details about weak authentication and marked the vulnerability as actively exploited with an exploit available.
Initial creation