Lucene search

K
zdiAnonymousZDI-21-1225
HistoryOct 21, 2021 - 12:00 a.m.

Microsoft SharePoint SetVariableActivity Deserialization of Untrusted Data Remote Code Execution Vulnerability

2021-10-2100:00:00
Anonymous
www.zerodayinitiative.com
29

0.163 Low

EPSS

Percentile

96.0%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the Microsoft.SharePoint.WorkflowActions.SetVariableActivity class. A crafted SetVariableActivity element can result in instantiation of an arbitrary .NET type. An attacker can leverage this vulnerability to execute code in the context of the web service account.