CVE-2021-28474HighCVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? In a network-based attack, an authenticated attacker can gain access to create a site and could execute code remotely within the SharePoint Server.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB5001917 (Security Update) — fixed build 16.0.5161.1000 KB5001916 (Security Update) — fixed build 16.0.10374.20000 KB5001935 (Security Update) — fixed build 15.0.5345.1000
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28474
- patchhttps://www.microsoft.com/download/details.aspx?familyid=650bb002-b472-4d9b-b36e-d960150b2ab7
- patchhttps://www.microsoft.com/download/details.aspx?familyid=0036da36-a42a-47e3-855d-9485daf73539
- patchhttps://www.microsoft.com/download/details.aspx?familyid=6830da9c-09be-44a0-a565-03638b030d89