CVE-2020-17120: Microsoft SharePoint Information Disclosure Vulnerability
Overview
- Severity
- Medium (CVSS 5.3)
- CVSS Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Information Disclosure
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2020-Dec
- Released
- 2020-12-08
- EPSS Score
- 12.69% (percentile: 94.0%)
FAQ
What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability relates to SQL table columns that would normally be restricted.
Affected Products (4)
Microsoft Office
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Foundation 2010 Service Pack 2
- Microsoft SharePoint Server 2019
Security Updates (7)
Acknowledgments
Yuhao Weng (<a href="https://twitter.com/cjm00nw">@cjm00nw</a>) of <a href="https://www.sangfor.com/">Sangfor</a> & Steven Seeley (<a href="https://twitter.com/steventseeley">@ϻг_ϻε</a>) & Zhiniang Peng(<a href="https://twitter.com/edwardzpeng">@edwardzpeng</a>)
Revision History
- 2020-12-08: Information published.