CVE-2020-16952

Scores

EPSS

0.778medium77.8%
0%20%40%60%80%100%

Percentile: 77.8%

CVSS

7.8high3.x
0246810

CVSS Score: 7.8/10

All CVSS Scores

CVSS 3.x
7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS 2.0
6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Description

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.

Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint.

The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

msrcnvd

CWEs

CWE-346

Related Vulnerabilities

Vulnerable Software (59)

Type: Configuration

Vendor: microsoft

Product: sharepoint_enterprise_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: sharepoint_foundation

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Configuration

Vendor: microsoft

Product: sharepoint_server

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:microsoft:sharepoin...

Source: nvd

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10417.20018

Operating System: Windows 10417 build 20018

Identifier: KB5002729

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10390.20000

Operating System: Windows 10390 build 20000

Identifier: KB5002258

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10385.20001

Operating System: Windows 10385 build 20001

Identifier: KB5002180

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10417.20037

Operating System: Windows 10417 build 20037

Identifier: KB5002754

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Version: 16.0.10399.20005

Operating System: Windows 10399 build 20005

Identifier: KB5002402

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4493194

Source: msrc

Type: Windows KB

Vendor: Microsoft

Product: Windows

Operating System: Windows

Identifier: KB4486751

Source: msrc