Executive brief
Microsoft SharePoint, a widely used platform for document management and team collaboration, contains a security flaw that could allow an authorized user to gain higher-level administrative permissions. By exploiting this vulnerability, an attacker with basic access could potentially take full control of the SharePoint environment, leading to the unauthorized access, modification, or deletion of sensitive corporate data. This poses a significant risk to organizational data integrity and confidentiality.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in Microsoft Office SharePoint. The flaw is triggered when the application improperly processes specially crafted serialized data sent over the network. An attacker must be authenticated with low-level privileges to exploit this issue. Successful exploitation allows the attacker to achieve elevation of privilege, potentially gaining full control over the affected SharePoint server (Confidentiality, Integrity, and Availability impact are all rated as High). Microsoft has released security updates to address this vulnerability; users should refer to the MSRC update guide for specific patch details.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: disclosed: Initial publication of CVE-2026-45484 by Microsoft.
- 2026-06-09: advisory: NVD record published.