CVE-2021-42320HighCVSS 8.0
Microsoft SharePoint Server Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to the target site, with the permission to modify their Display Name within SharePoint.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002055 (Security Update) — fixed build 16.0.5254.1000 KB5002054 (Security Update) — fixed build 16.0.10381.20001 KB5002045 (Security Update) — fixed build 16.0.14326.20620
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-42320
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=2b507dbf-c420-47ed-b73b-730eb4e8e89a
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=b370a437-4452-46ed-933d-612d0a10bfc0
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=c7e6c52a-88f0-484a-99c6-a2093a9d373a