Microsoft SharePoint Server Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server. An attacker who successfully exploited this vulnerability could execute malicious code on a vulnerable server in the context of the SharePoint application pool account. To exploit this vulnerability, an authenticated attacker would need to create a page specifically designed to cause a server-side request. The attacker would then send a specially-crafted message to perform a server-side request forgery attack. The update addresses the vulnerability by modifying how Microsoft SharePoint Server manages server authentication.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2013 Service Pack 1
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2010 Service Pack 2
✅ Remediation
KB4461541 (Security Update) KB4461558 (Security Update) KB4461465 (Security Update)
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2018-8635
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=1d2333ca-bd80-46e6-8c88-cbc9a81d4ced
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=e1c69c85-3f0b-4519-8f71-31c9554e122f
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=a72937b9-53e0-428b-bcab-988a4da49902