CVE-2020-1440HighCVSS 6.3
Microsoft SharePoint Server Tampering Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user. The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2013 Service Pack 1
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2010 Service Pack 2
- Microsoft SharePoint Server 2019
✅ Remediation
KB4484506 (Security Update) KB4484515 (Security Update) KB4484505 (Security Update) KB4486664 (Security Update)
🔗 References (8)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1440
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=67aa298e-47b1-4aaa-8a1c-ebacea64a4da
- referencehttps://support.microsoft.com/kb/4484506
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=55d9924d-418f-40ef-9eb3-3fb461a4b517
- referencehttps://support.microsoft.com/help/4484515
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=96f3322f-2160-43d8-8370-df405446eab2
- referencehttps://support.microsoft.com/kb/4484505
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=6fcfc474-f092-454a-9dfa-7f3469c0aebf