Lucene search

K
zdiAnonymousZDI-21-574
HistoryMay 13, 2021 - 12:00 a.m.

Microsoft SharePoint Server-Side Control Interpretation Conflict Remote Code Execution Vulnerability

2021-05-1300:00:00
Anonymous
www.zerodayinitiative.com
49

0.013 Low

EPSS

Percentile

85.7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of server-side controls. By specifying a control using a non-canonical string, an unsafe server-side control can be instantiated. An attacker can leverage this vulnerability to execute code in the context of the service account.