CVE-2019-1261High
Microsoft SharePoint Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF). To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page. The security update addresses the vulnerability by helping to ensure that SharePoint Server properly sanitizes user web requests.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4475590 (Security Update) KB4475596 (Security Update) KB4484098 (Security Update)
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-1261
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7d91d11b-6c09-4f22-802b-bd4e8e7a6ea2
- referencehttps://support.microsoft.com/help/4475590
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ac9ab481-f6e6-4a9a-bd3b-226e9a604e6c
- referencehttps://support.microsoft.com/help/4475596
- patchhttps://www.microsoft.com/download/details.aspx?familyid=10362533-7c43-46ff-bb5d-e7519533e73e
- referencehttps://support.microsoft.com/help/4484098