CVE-2021-24066HighCVSS 8.8
Microsoft SharePoint Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What is the attack vector for this vulnerability? In a network-based attack an attacker would need to have the privileges to create a site. By creating a site using specific code, the attacker could execute code remotely on the target server.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4493195 (Security Update) KB4493194 (Security Update) KB4493223 (Security Update) KB4493210 (Security Update)
🔗 References (9)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-24066
- patchhttps://www.microsoft.com/download/details.aspx?familyid=fa1649de-dffb-4e32-9459-eb116767610b
- referencehttps://support.microsoft.com/help/4493195
- patchhttps://www.microsoft.com/download/details.aspx?familyid=8d1d0c3f-57e3-45a2-8045-c435d45c1e16
- referencehttps://support.microsoft.com/help/4493194
- patchhttps://www.microsoft.com/download/details.aspx?familyid=5de7e425-27e9-48a8-990d-3e8d0378b40c
- referencehttps://support.microsoft.com/help/4493223
- patchhttps://www.microsoft.com/download/details.aspx?familyid=f407b400-72af-409b-a03c-d638ab6a0fe9
- referencehttps://support.microsoft.com/help/4493210