Executive brief
Microsoft Office SharePoint is a widely-used enterprise collaboration and document management platform. A deserialization vulnerability allows an authorized attacker to execute arbitrary code on the server, potentially leading to unauthorized access to sensitive business data, disruption of services, or lateral movement within corporate networks.
Technical details
The vulnerability is a deserialization of untrusted data flaw in Microsoft Office SharePoint that allows authenticated attackers to achieve remote code execution. The attack requires network access and valid authorization credentials to the SharePoint instance. An attacker can craft malicious serialized objects that, when deserialized by the application, trigger arbitrary code execution with the privileges of the SharePoint service account. Patches addressing this vulnerability are available from Microsoft.
Affected products
- Microsoft Office SharePoint <UNKNOWN>
Timeline
- 2026-08-11: disclosed
- 2026-08-11: advisory