CVE-2020-0933High
Microsoft SharePoint Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
An information disclosure vulnerability exists in SharePoint Server. An attacker who exploited this vulnerability could read arbitrary files on the server. To exploit the vulnerability, an attacker would need to send a specially crafted request to a susceptible SharePoint Server instance. The update addresses the vulnerability by changing how affected APIs process requests.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4484299 (Security Update) KB4484292 (Security Update) KB4484321 (Security Update)
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-0933
- patchhttps://www.microsoft.com/download/details.aspx?familyid=287fd0bb-b3ce-4fe8-b4e4-c0396d3c82d4
- patchhttps://www.microsoft.com/download/details.aspx?familyid=bbb37530-d5f6-4160-ab9d-6257e98319cd
- patchhttps://www.microsoft.com/download/details.aspx?familyid=ab7bf381-3fc6-4c2f-bdcf-72022fa5be29