Lucene search

K
cve[email protected]CVE-2023-38177
HistoryNov 14, 2023 - 6:15 p.m.

CVE-2023-38177

2023-11-1418:15:51
CWE-502
web.nvd.nist.gov
133
cve-2023-38177
microsoft
sharepoint
server
remote code execution
vulnerability
nvd

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.3%

Microsoft SharePoint Server Remote Code Execution Vulnerability

Affected configurations

Vulners
NVD
Node
microsoftmicrosoft_sharepoint_enterprise_server_2016Range16.0.016.0.5422.1000
OR
microsoftmicrosoft_sharepoint_server_2019Range16.0.016.0.10404.20003
OR
microsoftsharepoint_serverRange16.0.016.0.16731.20350
VendorProductVersionCPE
microsoftmicrosoft_sharepoint_enterprise_server_2016*cpe:2.3:a:microsoft:microsoft_sharepoint_enterprise_server_2016:*:*:*:*:*:*:*:*
microsoftmicrosoft_sharepoint_server_2019*cpe:2.3:a:microsoft:microsoft_sharepoint_server_2019:*:*:*:*:*:*:*:*
microsoftsharepoint_server*cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Microsoft",
    "product": "Microsoft SharePoint Enterprise Server 2016",
    "cpes": [
      "cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "16.0.0",
        "lessThan": "16.0.5422.1000",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft SharePoint Server 2019",
    "cpes": [
      "cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "16.0.0",
        "lessThan": "16.0.10404.20003",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Microsoft",
    "product": "Microsoft SharePoint Server Subscription Edition",
    "cpes": [
      "cpe:2.3:a:microsoft:sharepoint_server:-:*:*:*:subscription:*:*:*"
    ],
    "platforms": [
      "x64-based Systems"
    ],
    "versions": [
      {
        "version": "16.0.0",
        "lessThan": "16.0.16731.20350",
        "versionType": "custom",
        "status": "affected"
      }
    ]
  }
]

6.8 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

26.3%