cbcvebase.
CVE-2018-0910
published 2018-03-14

CVE-2018-0910: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted…

PriorityP349high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
4.71%
90.8th percentile
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923, CVE-2018-0944 and CVE-2018-0947.

Affected

6 ranges
VendorProductVersion rangeFixed in
microsoftproject_server
microsoftsharepoint_enterprise_server
microsoftsharepoint_enterprise_server
microsoft_corporationmicrosoft_sharepoint
msrcmicrosoft_project_server_2013_service_pack_1
msrcmicrosoft_sharepoint_enterprise_server_2016

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.