Executive brief
Microsoft SharePoint Server contains a code injection vulnerability (CWE-94) that allows an authenticated attacker with Site Owner privileges to execute code remotely on the server. The vulnerability stems from improper control of generation of code.
Affected products
- Microsoft SharePoint Enterprise Server 2016 -
- Microsoft SharePoint Server 2019 -
- Microsoft SharePoint Server Subscription Edition -
Timeline
- 2023-05-09: disclosed: NVD Published Date
- 2024-03-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-04-16: other: CISA Due Date for remediation