CVE-2020-1025
published 2020-07-14CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.85%
92.4th percentile
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access.
To exploit this vulnerability, an attacker would need to modify the token.
The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | lync | — | — |
| microsoft | microsoft_lync_server_2013 | < publication | publication |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | skype_for_business | — | — |
| microsoft | skype_for_business | — | — |
| microsoft | skype_for_business_server_2015_cu_8 | >= 2015 CU 8 < publication | publication |
| microsoft | skype_for_business_server_2019_cu2 | >= 7.0.0 < publication | publication |
| msrc | microsoft_lync_server_2013 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | skype_for_business_server_2015_cu_8 | — | — |
| msrc | skype_for_business_server_2019_cu2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability involves improper OAuth token validation in Microsoft SharePoint Server and Skype for Business Server; detection should focus on anomalous or modified OAuth tokens being presented to these services. ↗
- →Monitor for authentication bypass events or unexpected privilege escalation on SharePoint Server and Skype for Business Server, particularly where OAuth token modification may have occurred. ↗
- ·Exploit status is publicly disclosed: No and exploited: No at time of advisory; exploitation rated 'Less Likely' for both latest and older software releases, reducing immediate urgency but patching is still recommended. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office Elevation of Privilege Vulnerability
vendor_msrc·2020-07-14·CVSS 9.8
CVE-2020-1025 [CRITICAL] Microsoft Office Elevation of Privilege Vulnerability
Microsoft Office Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access.
To exploit this vulnerability, an attacker would need to modify the token.
The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
Skype for Business: Skype for Business
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Referenc
GHSA
GHSA-5xrx-pfvm-p5p8: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation
ghsa_unreviewed·2022-05-24
CVE-2020-1025 [HIGH] CWE-20 GHSA-5xrx-pfvm-p5p8: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation, aka 'Microsoft Office Elevation of Privilege Vulnerability'.
No detection rules found.
No public exploits indexed.
Trendmicro
Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
blogs_trendmicro·2020-07-14·CVSS 7.8
[HIGH] Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
# Fixes for ‘Wormable’ Windows RCE in July Patch Tuesday
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs were disclosed through Trend Micro’s Zero Day Initiative (ZDI) program.
By: Trend Micro
2020/07/14
Read time: ( words)
Save to Folio
There has been a common vulnerabilities and exposures (CVE) fixing trend in 2020 Patch Tuesdays. For instance, Microsoft has patched roughly more than 100 vulnerabilities per month in recent bulletins. Similarly, the July update issues 123 patches, including fixes in RemoteFX vGPU, Microsoft Office, Microsoft Windows, OneDrive, and Jet Database Engine.
The patches address 18 vulnerabilities rated Critical and 105 that were rated Important in severity. A total of eight CVEs wer
Bugzilla
CVE-2020-25650 spice-vdagent: memory DoS via arbitrary entries in active_xfers hash table
bugzilla·2020-10-08·CVSS 5.5
CVE-2020-25650 [MEDIUM] CVE-2020-25650 spice-vdagent: memory DoS via arbitrary entries in active_xfers hash table
CVE-2020-25650 spice-vdagent: memory DoS via arbitrary entries in active_xfers hash table
The following flaw was reported by SUSE Security:
The `spice-vdagentd` maintains a hash map named `active_xfers` that maps `task_ids` to UNIX domain socket connections they belong to. These `task_ids`
refer to ongoing file transfers from the host to the virtual machine. An arbitrary client connected to `spice-vdagentd` via a UNIX domain socket can trigger an entry into this hash map, without the requirement that the client is associated with the currently active graphical session (function `do_agent_file_xfer_status`, specifically `vdagentd.c:1025`). There is no limit on the maximum amount of file transfers ongoing in parallel and there are no timeouts applied for a file transfer to be finished.
Th
2020-07-14
Published