CVE-2020-17089
published 2020-12-10CVE-2020-17089: Microsoft SharePoint Elevation of Privilege Vulnerability
PriorityP342high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
2.53%
83.3th percentile
Microsoft SharePoint Elevation of Privilege Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2010_service_pack_2 | >= 13.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8qmw-pm39-cgxw: , aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-17089 [HIGH] CWE-269 GHSA-8qmw-pm39-cgxw: , aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'
, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Microsoft
Microsoft SharePoint Elevation of Privilege Vulnerability
vendor_msrc·2020-12-08·CVSS 7.1
CVE-2020-17089 [HIGH] Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely
Reference: https://www.microsoft.com/download/details.aspx?familyid=9f6f9da2-92d0-4872-b1cc-4718a2381530
Reference: https://support.microsoft.com/kb/4486753
Reference: https://www.microsoft.com/download/details.aspx?familyid=a54b63ac-4c27-4e32-89b4-4a86b2a90f20
Reference: https://support.microsoft.com/kb/4486751
Reference: https://www.microsoft.com/download/details.aspx?familyid=4abefe8e-b03a-47b2-be74-e57a2a7610a4
Reference: https://suppor
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-12-10
Published