CVE-2023-21743CriticalCVSS 5.3

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Published
January 10, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Are any additional steps required to protect my SharePoint farm after installing the January 10, 2023 security update for SharePoint Server? Yes. Customers must also trigger a SharePoint upgrade action included in this update to protect their SharePoint farm. The upgrade action can be triggered by running the SharePoint Products Configuration Wizard, the Upgrade-SPFarm PowerShell cmdlet, or the "psconfig.exe -cmd upgrade -inplace b2b" command on each SharePoint server after installing the update.

How could an attacker exploit this vulnerability? In a network-based attack, an unauthenticated attacker could bypass authentication and make an anonymous connection.

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An unauthenticated attacker is able to bypass the expected user access.

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002338 (Security Update) — fixed build 16.0.5378.1000 KB5002329 (Security Update) — fixed build 16.0.10394.20021 KB5002331 (Security Update) — fixed build 16.0.15601.20418

🔗 References (7)