CVE-2021-1726: Microsoft SharePoint Server Spoofing Vulnerability

Overview

Severity
High (CVSS 8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Spoofing
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Feb
Released
2021-02-09
EPSS Score
6.52% (percentile: 91.1%)

FAQ

What is the nature of the spoofing? An authenticated attacker could manipulate a SharePoint blog sharing functionality to trigger messaging or a link that appears to be from the SharePoint target site.

Affected Products (4)

Microsoft Office

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Foundation 2010 Service Pack 2
  • Microsoft SharePoint Foundation 2013 Service Pack 1

Security Updates (4)

Acknowledgments

Huynh Phuoc Hung, <a href="https://twitter.com/hph0var">@hph0var</a>

Revision History

  • 2021-02-09: Information published.