CVE-2022-21837HighCVSS 8.3

Microsoft SharePoint Server Remote Code Execution Vulnerability

Published
January 11, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

How could an attacker exploit the vulnerability? An authenticated attacker with access to the domain could perform remote code execution on the SharePoint server to elevate themselves to SharePoint admin.

🎯 Affected products4

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002113 (Security Update) — fixed build 16.0.5266.1000 KB5002109 (Security Update) — fixed build 16.0.10382.20004 KB5002111 (Security Update) — fixed build 16.0.14326.20714 KB5002127 (Security Update) — fixed build 15.0.5415.1000

🔗 References (9)