CERT-In Vulnerability Note
CIVN-2020-0435
Remote code Execution Vulnerability in Microsoft SharePoint
Original Issue Date:December 11, 2020
Severity Rating: HIGH
Software Affected
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Enterprise Server 2016
Overview
Multiple vulnerabilities exist in Microsoft SharePoint which could allow a remote attacker to execute arbitrary code on a targeted system.
Description
These vulnerabilities exist due to improper input validation in Microsoft SharePoint. A remote attacker can send a specially crafted request and execute arbitrary code on the targeted system.
Successful exploitation of these vulnerabilities may result in complete compromise of vulnerable system.
Solution
Apply appropriate patches as mentioned by vendor
https://msrc.microsoft.com/update-guide/en-us/
Vendor Information
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17118
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17121
References
Microsoft
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17118
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17121
CVE Name
CVE-2020-17118
CVE-2020-17121
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|