Microsoft SharePoint Server Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is user tokens and other potentially sensitive information.
According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability? A successful attacker could gain the Domain SID prefix for the targeted site.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002397 (Security Update) — fixed build 16.0.5395.1000 KB5002389 (Security Update) — fixed build 16.0.10398.20000 KB5002390 (Security Update) — fixed build 16.0.16130.20420
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24954
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7a299fb3-33f2-4417-809d-7bf31da6d14e
- referencehttps://support.microsoft.com/help/5002397
- patchhttps://www.microsoft.com/download/details.aspx?familyid=c9190144-e85b-4ded-9b6f-cc9b295054f3
- referencehttps://support.microsoft.com/help/5002389
- patchhttps://www.microsoft.com/download/details.aspx?familyid=1aac4804-a1a0-4d40-8d9a-a1ac25def0b0
- referencehttps://support.microsoft.com/help/5002390