CVE-2021-42320: Microsoft SharePoint Server Spoofing Vulnerability
Overview
- Severity
- High (CVSS 8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Spoofing
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2021-Dec
- Released
- 2021-12-14
- EPSS Score
- 0.59% (percentile: 69.2%)
FAQ
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must be authenticated to the target site, with the permission to modify their Display Name within SharePoint.
Affected Products (3)
Microsoft Office
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
Security Updates (3)
Acknowledgments
Huynh Phuoc Hung, <a href="https://twitter.com/hph0var">@hph0var</a>
Revision History
- 2021-12-14: Information published.