CVE-2023-33165: Microsoft SharePoint Server Security Feature Bypass Vulnerability

Overview

Severity
Medium (CVSS 4.3)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2023-Jul
Released
2023-07-11
EPSS Score
1.22% (percentile: 79.0%)

FAQ

According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability? The attacker who successfully exploits the vulnerability could download files without the access being logged. What kind of security feature could be bypassed by successfully exploiting this vulnerability? An attacker could bypass the logging of downloaded files.

Affected Products (2)

Microsoft Office

  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

Security Updates (2)

Acknowledgments

Sergey Egorov, Anonymous

Revision History

  • 2023-07-11: Information published.