Executive brief
Microsoft Office SharePoint contains a flaw in how it processes serialized data from network requests. An authorized user can send specially crafted data to the server that causes it to execute arbitrary code, potentially compromising the integrity and confidentiality of SharePoint servers and the data they store.
Technical details
This vulnerability exists in Microsoft Office SharePoint's deserialization handling, which fails to properly validate untrusted data before reconstruction into objects. The flaw allows an authenticated attacker to send malicious serialized payloads over the network that trigger remote code execution on the server. An attacker must have valid authentication credentials to exploit this vulnerability. Patches are expected from Microsoft's security team for affected versions.
Affected products
- Microsoft Office SharePoint <UNKNOWN>
Timeline
- 2026-08-11: disclosed