Executive brief
Microsoft Office SharePoint is a collaborative document and content management platform used by organizations to store and share business files and information. This vulnerability allows an authenticated attacker to execute malicious code on servers running SharePoint by sending specially crafted network requests that exploit unsafe deserialization, potentially compromising data confidentiality and system availability.
Technical details
The vulnerability is a deserialization flaw in Microsoft Office SharePoint that permits remote code execution when processing untrusted serialized objects. An authorized attacker can craft malicious serialized data and transmit it over the network to trigger arbitrary code execution on affected SharePoint servers. The attack requires authentication and network connectivity to the vulnerable SharePoint instance. Exploitation allows an attacker to run commands with the privileges of the SharePoint application process. Microsoft has issued security patches to address this vulnerability.
Affected products
- Microsoft Office SharePoint
Timeline
- 2026-08-11: disclosed