CVE-2022-21968: Microsoft SharePoint Server Security Feature Bypass Vulnerability

Overview

Severity
Medium (CVSS 4.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2022-Feb
Released
2022-02-08
EPSS Score
1.02% (percentile: 77.2%)

FAQ

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must have read access to the target site within SharePoint. What kind of security feature could be bypassed by successfully exploiting this vulnerability? The attacker would be able to bypass the protection in SharePoint blocking the HTTP request based on IP range. If an attacker successfully exploited this vulnerability, they could validate the presence or absence of an HTTP endpoint within the blocked IP range.

Affected Products (4)

Microsoft Office

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Foundation 2013 Service Pack 1

Security Updates (4)

Acknowledgments

Steven Seeley (mr_me)

Revision History

  • 2022-02-08: Information published.