CVE-2021-40487HighCVSS 8.1
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit this vulnerability? In a network-based attack, an authenticated attacker can gain access to create a site and could execute code remotely within the SharePoint Server.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2019
✅ Remediation
KB5002029 (Security Update) — fixed build 16.0.5227.1000 KB5002028 (Security Update) — fixed build 16.0.10379.20000 KB5002042 (Security Update) — fixed build 15.0.5389.1000
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40487
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=dc08d7a5-c213-4842-8824-e43876d474a1
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=48b05306-b1ff-468c-8b77-1d477549f14c
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=6b6c0519-83e6-451c-a793-084d12a7eb54