Executive brief
Microsoft Office SharePoint Server is a collaboration platform used by enterprises to manage documents and team content. A flaw in how SharePoint processes untrusted data allows an authenticated attacker to execute arbitrary code on servers, potentially compromising sensitive business documents and enabling lateral movement through corporate networks.
Technical details
The vulnerability stems from unsafe deserialization of untrusted data in Microsoft Office SharePoint. An authenticated attacker with network access can send specially crafted serialized objects that, when deserialized by the SharePoint application, trigger remote code execution. This is a pre-authentication attack requiring valid credentials but no additional user interaction. Successful exploitation grants the attacker the ability to execute arbitrary commands with the privileges of the SharePoint service account.
Affected products
- Microsoft Office SharePoint <UNKNOWN>
Timeline
- 2026-08-11: disclosed