Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
| Vendor | Product | Versions |
|---|---|---|
| microsoft | sharepoint_server | 16.0.0, 16.0.0, 16.0.0 |
Added detailed technical context from real-world incident discovery by Mandiant/Google FLARE, clarified affected SharePoint versions (2016, 2019, Subscription Edition), added MITRE ATT&CK technique T1190 (Exploit Public-Facing Application), and included interim mitigation guidance (AMSI Full Request Body Scan).
Enhanced description with explicit confirmation of remote exploitation without authentication and added CISA KEV catalog tag to reflect confirmed active exploitation.
Updated affected versions, severity to HIGH, added new CWEs, and provided fixed version numbers.
Updated severity to CRITICAL, added affected versions, new CWEs, and included the patch available date.
Updated severity to HIGH, marked exploit as available, and added new tags related to the vulnerability.
Updated severity to CRITICAL, changed description for more technical detail, and noted that no exploit is available.
Initial creation