Lucene search

K
zdiAnonymousZDI-22-074
HistoryJan 14, 2022 - 12:00 a.m.

Microsoft SharePoint Server-Side Control Improper Input Validation Remote Code Execution Vulnerability

2022-01-1400:00:00
Anonymous
www.zerodayinitiative.com
17

0.038 Low

EPSS

Percentile

91.9%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of server-side controls. An unsafe server-side control can be instantiated if it is specified as a child of a permitted control. An attacker can leverage this vulnerability to execute code in the context of the service account.