Executive brief
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to properly validate the source markup of an application package. An attacker can exploit this to execute arbitrary code within the context of the SharePoint application pool and the server farm account.
Affected products
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Foundation 2013 Service Pack 1
- Microsoft SharePoint Server 2010 Service Pack 2
- Microsoft SharePoint Server 2019
Timeline
- 2019-03-05: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog