CVE-2022-22005HighCVSS 8.8
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated and possess the permissions for page creation to be able to exploit this vulnerability.
🎯 Affected products4
- Microsoft SharePoint Enterprise Server 2013 Service Pack 1
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002136 (Security Update) — fixed build 16.0.5278.1000 KB5002120 (Security Update) — fixed build 15.0.5423.1000 KB5002135 (Security Update) — fixed build 16.0.10383.20001 KB5002145 (Security Update) — fixed build 16.0.14326.20742
🔗 References (6)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-22005
- patchhttps://www.microsoft.com/download/details.aspx?familyid=977f2baf-941b-423a-bc79-8383a844310a
- patchhttps://www.microsoft.com/download/details.aspx?familyid=931bc018-8f42-4e39-ae81-ebdb7e4180f3
- patchhttps://www.microsoft.com/download/details.aspx?familyid=9062c391-efc6-40d0-b679-e7a31d2bb294
- referencehttps://support.microsoft.com/kb/5002135
- patchhttps://www.microsoft.com/download/details.aspx?familyid=e66ce694-33fb-41c6-ac72-535d3d6c579d