Executive brief
Microsoft Office SharePoint, a widely used platform for document management and team collaboration, is affected by a security vulnerability that could allow an authorized user to perform spoofing attacks. An attacker with basic user permissions could exploit this to display fraudulent content or misrepresent information to other users on the network. This could lead to internal misinformation or unauthorized data manipulation within the SharePoint environment.
Technical details
A cross-site scripting (XSS) vulnerability exists in Microsoft Office SharePoint due to improper neutralization of input during web page generation. An attacker with low-level authenticated privileges (PR:L) can exploit this flaw over the network without requiring user interaction (UI:N). While the Microsoft advisory also references CWE-502 (Deserialization of Untrusted Data), the primary impact described is spoofing via XSS. Successful exploitation allows the attacker to compromise the integrity and confidentiality of the session, potentially leading to unauthorized actions performed in the context of other users.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-06-09: advisory: Microsoft published the security advisory.