CVE-2021-1707HighCVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What is the attack vector for this vulnerability? In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4493163 (Security Update) KB4493162 (Security Update) KB4493187 (Security Update) KB4493175 (Security Update)
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1707
- patchhttps://www.microsoft.com/download/details.aspx?familyid=394b03f5-8ebd-44e4-b219-d394b58abc4c
- patchhttps://www.microsoft.com/download/details.aspx?familyid=bf887ae8-bfd5-4e80-b07d-b52fb2be5326
- patchhttps://www.microsoft.com/download/details.aspx?familyid=5a23d645-68fc-4a13-9529-52b1a7f7419c
- patchhttps://www.microsoft.com/download/details.aspx?familyid=35b76014-32c6-40a4-bf16-cb596b52df20