Lucene search

K
zdiAnonymousZDI-21-828
HistoryJul 19, 2021 - 12:00 a.m.

Microsoft SharePoint SetVariableActivity Deserialization of Untrusted Data Remote Code Execution Vulnerability

2021-07-1900:00:00
Anonymous
www.zerodayinitiative.com
163

0.023 Low

EPSS

Percentile

89.8%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the Microsoft.SharePoint.WorkflowActions.SetVariableActivity class. A crafted SetVariableActivity element can result in instantiation of an arbitrary .NET type. An attacker can leverage this vulnerability to execute code in the context of the web service account.