Executive brief
Microsoft Office SharePoint contains a flaw in how it handles untrusted data during deserialization, allowing an authorized attacker to impersonate legitimate users or services. An attacker with valid SharePoint credentials could exploit this to send fraudulent messages or perform actions appearing to come from other users, potentially damaging trust in communications and enabling social engineering attacks.
Technical details
A deserialization vulnerability exists in Microsoft Office SharePoint where untrusted serialized data is processed without proper validation. An authenticated attacker can craft malicious serialized payloads to bypass authentication checks and perform spoofing operations over the network. The vulnerability requires the attacker to have valid SharePoint credentials and network access to the affected SharePoint instance. Successful exploitation allows the attacker to forge the identity of legitimate users or services, potentially leading to unauthorized actions attributed to other accounts.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed