cbcvebase.
CVE-2020-1025
published 2020-07-14

CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftlync
microsoftmicrosoft_lync_server_2013< publicationpublication
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < publicationpublication
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < publicationpublication
microsoftsharepoint_enterprise_server
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftskype_for_business
microsoftskype_for_business
microsoftskype_for_business_server_2015_cu_8>= 2015 CU 8 < publicationpublication
microsoftskype_for_business_server_2019_cu2>= 7.0.0 < publicationpublication
msrcmicrosoft_lync_server_2013
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019
msrcskype_for_business_server_2015_cu_8
msrcskype_for_business_server_2019_cu2