CVE-2023-33165HighCVSS 4.3

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Published
July 11, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker who successfully exploits the vulnerability could download files without the access being logged.

What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker could bypass the logging of downloaded files.

🎯 Affected products2

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002423 (Security Update) — fixed build 16.0.10400.20008 KB5002424 (Security Update) — fixed build 16.0.16130.20642

🔗 References (3)