CVE-2020-16952

Scores

EPSS

0.751medium75.1%
0%20%40%60%80%100%

Percentile: 75.1%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.

Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.

The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

msrcnvd

CWEs

CWE-346

Related Vulnerabilities

Vulnerable Software (64)

Type: Configuration

Vendor: *

Product: sharepoint_enterprise_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_foundation

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Configuration

Vendor: *

Product: sharepoint_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4486694

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4486676

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10402.20016

Operating System: Windows 10402 build 20016

Identifier: KB5002472

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4493162

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4493230

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10416.20050

Operating System: Windows 10416 build 20050

Identifier: KB5002678

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10394.20021

Operating System: Windows 10394 build 20021

Identifier: KB5002329

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10392.20000

Operating System: Windows 10392 build 20000

Identifier: KB5002294

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10391.20000

Operating System: Windows 10391 build 20000

Identifier: KB5002278

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10383.20001

Operating System: Windows 10383 build 20001

Identifier: KB5002135

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10395.20001

Operating System: Windows 10395 build 20001

Identifier: KB5002342

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4493194

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10382.20004

Operating System: Windows 10382 build 20004

Identifier: KB5002109

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10379.20000

Operating System: Windows 10379 build 20000

Identifier: KB5002028

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10377.20000

Operating System: Windows 10377 build 20000

Identifier: KB5002000

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10412.20001

Operating System: Windows 10412 build 20001

Identifier: KB5002615

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 10378.20002

Operating System: Windows 10378 build 20002

Identifier: KB5002018

Source: msrc