CVE-2021-27076HighCVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
🎯 Affected products4
- Microsoft Business Productivity Servers 2010 Service Pack 2
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB4493232 (Security Update) — fixed build 16.0.5134.1000 KB4493230 (Security Update) — fixed build 16.0.10372.20000 KB3101541 (Security Update) — fixed build 14.0.7267.5000 KB4493238 (Security Update) — fixed build 15.0.5327.1000
🔗 References (10)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-27076
- patchhttps://www.microsoft.com/download/details.aspx?familyid=35544dda-5748-488f-ba0a-3cb0598bd49c
- referencehttps://support.microsoft.com/kb/4493232
- patchhttps://www.microsoft.com/download/details.aspx?familyid=93aae8bc-8253-4df6-a1cf-7554eb0f8eda
- referencehttps://support.microsoft.com/kb/4493230
- referencehttps://support.microsoft.com/help/4493230
- patchhttps://www.microsoft.com/download/details.aspx?familyid=979f6d53-3819-408b-b9a3-07cfdd720ad1
- referencehttps://support.microsoft.com/help/3101541
- patchhttps://www.microsoft.com/download/details.aspx?familyid=2f847aa5-7e0a-4668-b5ea-e59d5e4d6885
- referencehttps://support.microsoft.com/kb/4493238