CVE-2020-1595Download of Code Without Integrity Check in Microsoft Sharepoint Enterprise Server 2013 Service Pack 1

Severity
8.8HIGHNVD
CNA9.9
EPSS
0.5%
top 32.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 24

Description

A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user access a susceptible API on an affected version of SharePoint with specially-formatted input. The security update addresses the vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages7 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-85x5-vr9q-4m59: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft Share2022-05-24
CVEList
Microsoft SharePoint Remote Code Execution Vulnerability2020-09-11

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability2020-09-08
CVE-2020-1595 — Microsoft vulnerability | cvebase