CVE-2018-8635
Severity
8.8HIGH
EPSS
19.7%
top 4.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 12
Latest updateMay 13
Description
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages4 packages
▶CVEListV5microsoft/microsoft_sharepointEnterprise Server 2013 Service Pack 1, Enterprise Server 2016+1
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-grqw-w3g8-7m4m: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request↗2022-05-13
CVEList▶
CVE-2018-8635: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request↗2018-12-12