CVE-2021-43876HighCVSS 8.8
Microsoft SharePoint Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to the target site, with the rights to use the SharePoint Migration tool and the ability to create a new SharePoint site collection.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2013 Service Pack 1
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
✅ Remediation
KB5002055 (Security Update) — fixed build 16.0.5254.1000 KB5002008 (Security Update) — fixed build 15.0.5407.1000 KB5002054 (Security Update) — fixed build 16.0.10381.20001
🔗 References (4)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43876
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=2b507dbf-c420-47ed-b73b-730eb4e8e89a
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=d0a4e96a-08a3-4193-b4cd-fae097f43581
- patchhttps://www.microsoft.com/downloads/details.aspx?familyid=b370a437-4452-46ed-933d-612d0a10bfc0