Lucene search

K
zdiNguyễn Tiến Giang (@testanull) of STAR Labs SG Pte. Ltd.ZDI-23-883
HistoryJun 16, 2023 - 12:00 a.m.

(Pwn2Own) Microsoft SharePoint GenerateProxyAssembly Code Injection Remote Code Execution Vulnerability

2023-06-1600:00:00
Nguyễn Tiến Giang (@testanull) of STAR Labs SG Pte. Ltd.
www.zerodayinitiative.com
23
microsoft sharepoint
code injection
remote code execution
authentication bypass
generateproxyassembly
c# code
vulnerability

0.707 High

EPSS

Percentile

98.1%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the GenerateProxyAssembly method. The issue results from the lack of proper validation of a user-supplied string before using it to execute C# code. An attacker can leverage this vulnerability to execute code in the context of SharePoint farm service account.