CVE-2020-17118
published 2020-12-10CVE-2020-17118: Microsoft SharePoint Remote Code Execution Vulnerability
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.71%
88.6th percentile
Microsoft SharePoint Remote Code Execution Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2010_service_pack_2 | >= 13.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
56554, 56557, 56558, 56560 - 56562 and 56564
- →CVE-2020-17118 is a Remote Code Execution vulnerability in Microsoft SharePoint; Talos Snort rules 56554, 56557, 56558, 56560–56562, and 56564 provide coverage for exploitation attempts of vulnerabilities disclosed in the December 2020 Patch Tuesday, including this CVE. ↗
- ·Microsoft rates exploitation of CVE-2020-17118 as 'More Likely' for both latest and older software releases, despite no public exploit or in-the-wild exploitation confirmed at time of disclosure. ↗
- ·The Talos Snort rule set covers multiple December 2020 Patch Tuesday CVEs collectively; individual rule-to-CVE mapping for CVE-2020-17118 specifically is not confirmed in the source material. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v22m-mfm8-q276: , aka 'Microsoft SharePoint Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 8.1
CVE-2020-17121 [HIGH] GHSA-v22m-mfm8-q276: , aka 'Microsoft SharePoint Remote Code Execution Vulnerability'
, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17118.
GHSA
GHSA-9p83-qxxf-6fm5: , aka 'Microsoft SharePoint Remote Code Execution Vulnerability'
ghsa_unreviewed·2022-05-24·CVSS 8.8
CVE-2020-17118 [HIGH] GHSA-9p83-qxxf-6fm5: , aka 'Microsoft SharePoint Remote Code Execution Vulnerability'
, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17121.
Microsoft
Microsoft SharePoint Remote Code Execution Vulnerability
vendor_msrc·2020-12-08·CVSS 8.1
CVE-2020-17118 [HIGH] Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely
Reference: https://www.microsoft.com/download/details.aspx?familyid=9f6f9da2-92d0-4872-b1cc-4718a2381530
Reference: https://support.microsoft.com/kb/4486753
Reference: https://www.microsoft.com/download/details.aspx?familyid=a54b63ac-4c27-4e32-89b4-4a86b2a90f20
Reference: https://support.microsoft.com/kb/4486751
Reference: https://www.microsoft.com/download/details.aspx?familyid=4abefe8e-b03a-47b2-be74-e57a2a7610a4
Reference: https://support.
No detection rules found.
No public exploits indexed.
Trendmicro
December Patch Tuesday Fixes Exchange, SMB
blogs_trendmicro·2020-12-09·CVSS 6.6
[MEDIUM] December Patch Tuesday Fixes Exchange, SMB
# December Patch Tuesday Fixes Exchange, SMB
The last set of updates for the year includes 58 patches for the Microsoft Office suite.
By: Trend Micro
2020/12/09
Read time: ( words)
Save to Folio
Updated on 12/9/2020 02:37PM PST to include Trend Micro Deep Security and Vulnerability Protection rules.
The last set of updates for the year includes 58 patches for the Microsoft Office suite. Of the total number, nine have been rated Critical and 46 as Important. A significant number of updates fixes gaps in MS Exchange vulnerable to remote code execution (RCE) and information disclosure, as well as a server message block (SMB) gap also noted for the latter vulnerability. No zero days have been observed, though several vulnerabilities have been deemed as likely for abuse. Six of the total
Tenable
Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
blogs_tenable·2020-12-08·CVSS 7.4
[HIGH] Microsoft’s December 2020 Patch Tuesday Addresses 58 CVEs including CVE-2020-25705 (SAD DNS)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
December 2020 Patch Tuesday – 58 Vulnerabilities, 9 Critical, Windows Exchange, Hyper-V, SharePoint, Adobe
blogs_qualys·2020-12-08·CVSS 8.5
[HIGH] December 2020 Patch Tuesday – 58 Vulnerabilities, 9 Critical, Windows Exchange, Hyper-V, SharePoint, Adobe
This month’s Microsoft Patch Tuesday addresses 58 vulnerabilities with 9 of them labeled as Critical. The 9 Critical vulnerabilities cover Exchange, SharePoint, Hyper-V, Chakra Scripting, and several other workstation vulnerabilities. Adobe released patches today for Experience Manager, Prelude, Lightroom and pre-notification security advisory for Acrobat and Reader .
## Workstation Patches
Today’s Patch Tuesday fixes vulnerabilities that would impact workstations. The Office, Edge, Chakra vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Microsoft Exchange RCE
Microsoft patched five Remote Code Execution vu
Qualys
December 2020 Patch Tuesday – 58 Vulnerabilities, 9 Critical, Windows Exchange, Hyper-V, SharePoint, Adobe | Qualys
blogs_qualys·2020-12-08·CVSS 8.5
[HIGH] December 2020 Patch Tuesday – 58 Vulnerabilities, 9 Critical, Windows Exchange, Hyper-V, SharePoint, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 58 vulnerabilities with 9 of them labeled as Critical. The 9 Critical vulnerabilities cover Exchange, SharePoint, Hyper-V, Chakra Scripting, and several other workstation vulnerabilities. Adobe released patches today for Experience Manager, Prelude, Lightroom and pre-notification security advisory for Acrobat and Reader.
### Workstation Patches
Today’s Patch Tuesday fixes vulnerabilities that would impact workstations. The Office, Edge, Chakra vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Microsoft Exchange RCE
Microsoft patched five Remote Code Execution v
Talos
Microsoft Patch Tuesday (Dec. 2020) — Snort rules and notable vulnerabilities
blogs_talos·2020-12-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday (Dec. 2020) — Snort rules and notable vulnerabilities
## Microsoft Patch Tuesday (Dec. 2020) — Snort rules and notable vulnerabilities
By Jon Munshaw, with contributions from Bill Largent.
Microsoft released its monthly security update Tuesday, disclosing 58 vulnerabilities across its suite of products, the lowest number of vulnerabilities in any Patch Tuesday since January.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder are considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the SharePoint file-sharing service, the Windows Backup Engine and the Exchange mai
Talos
Microsoft Patch Tuesday (Dec. 2020) — Snort rules and notable vulnerabilities
blogs_talos·2020-12-08·CVSS 7.5
[HIGH] Microsoft Patch Tuesday (Dec. 2020) — Snort rules and notable vulnerabilities
By Jon Munshaw, with contributions from Bill Largent.
Microsoft released its monthly security update Tuesday, disclosing 58 vulnerabilities across its suite of products, the lowest number of vulnerabilities in any Patch Tuesday since January.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder are considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the SharePoint file-sharing service, the Windows Backup Engine and the Exchange mail server.
Talos also released a new set of SNORTⓇ rules that provide coverage for
2020-12-10
Published