CVE-2020-17121CriticalCVSS 8.8
Microsoft SharePoint Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What is the attack vector for this vulnerability? In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4493138 (Security Update) KB4493149 (Security Update) KB4486751 (Security Update) KB4486753 (Security Update)
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17121
- patchhttps://www.microsoft.com/download/details.aspx?familyid=259a4b86-7086-4240-8928-d40956abc4db
- referencehttps://support.microsoft.com/kb/4493138
- patchhttps://www.microsoft.com/download/details.aspx?familyid=4abefe8e-b03a-47b2-be74-e57a2a7610a4
- referencehttps://support.microsoft.com/kb/4493149
- patchhttps://www.microsoft.com/download/details.aspx?familyid=a54b63ac-4c27-4e32-89b4-4a86b2a90f20
- referencehttps://support.microsoft.com/kb/4486751
- patchhttps://www.microsoft.com/download/details.aspx?familyid=9f6f9da2-92d0-4872-b1cc-4718a2381530
- referencehttps://support.microsoft.com/kb/4486753