CVE-2022-21968HighCVSS 4.3

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Published
February 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must have read access to the target site within SharePoint.

What kind of security feature could be bypassed by successfully exploiting this vulnerability? The attacker would be able to bypass the protection in SharePoint blocking the HTTP request based on IP range. If an attacker successfully exploited this vulnerability, they could validate the presence or absence of an HTTP endpoint within the blocked IP range.

🎯 Affected products4

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Foundation 2013 Service Pack 1
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002136 (Security Update) — fixed build 16.0.5278.1000 KB5002135 (Security Update) — fixed build 16.0.10383.20001 KB5002145 (Security Update) — fixed build 16.0.14326.20742 KB5002155 (Security Update) — fixed build 15.0.5423.1000

🔗 References (6)