cbcvebase.
CVE-2020-1025
published 2020-07-14

CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An…

PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
5.85%
92.4th percentile
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftlync
microsoftmicrosoft_lync_server_2013< publicationpublication
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < publicationpublication
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftskype_for_business
microsoftskype_for_business
microsoftskype_for_business_server_2015_cu_8>= 2015 CU 8 < publicationpublication
microsoftskype_for_business_server_2019_cu2>= 7.0.0 < publicationpublication
msrcmicrosoft_lync_server_2013
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019
msrcskype_for_business_server_2015_cu_8
msrcskype_for_business_server_2019_cu2

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability involves improper OAuth token validation in Microsoft SharePoint Server and Skype for Business Server; detection should focus on anomalous or modified OAuth tokens being presented to these services.
  • Monitor for authentication bypass events or unexpected privilege escalation on SharePoint Server and Skype for Business Server, particularly where OAuth token modification may have occurred.
  • ·Exploit status is publicly disclosed: No and exploited: No at time of advisory; exploitation rated 'Less Likely' for both latest and older software releases, reducing immediate urgency but patching is still recommended.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.