CVE-2022-21968: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Overview
- Severity
- Medium (CVSS 4.3)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2022-Feb
- Released
- 2022-02-08
- EPSS Score
- 1.02% (percentile: 77.2%)
FAQ
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
The attacker must have read access to the target site within SharePoint.
What kind of security feature could be bypassed by successfully exploiting this vulnerability?
The attacker would be able to bypass the protection in SharePoint blocking the HTTP request based on IP range. If an attacker successfully exploited this vulnerability, they could validate the presence or absence of an HTTP endpoint within the blocked IP range.
Affected Products (4)
Microsoft Office
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Foundation 2013 Service Pack 1
Security Updates (4)
Acknowledgments
Steven Seeley (mr_me)
Revision History
- 2022-02-08: Information published.