CVE-2021-1707
published 2021-01-12CVE-2021-1707: Microsoft SharePoint Server Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
3.58%
88.1th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2010_service_pack_2 | >= 13.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < publication | publication |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < publication | publication |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2010_service_pack_2 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2021-01-12·CVSS 8.8
CVE-2021-1707 [HIGH] Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
FAQ: What is the attack vector for this vulnerability?
In a network-based attack an attacker could gain access to create a site and could execute code remotely. The attacker would need to have privileges.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;Older Software Release:Exploitation More Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=394b03f5-8ebd-44e4-b219-d394b58abc4c
Reference: https://www.microsoft.com/download/details.aspx?familyid=bf887ae8-bfd5-4e80-b07d-b52fb2be5326
Reference: https:/
GHSA
GHSA-33p3-36hv-c9p7: Microsoft SharePoint Server Remote Code Execution Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-1707 [HIGH] GHSA-33p3-36hv-c9p7: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
No detection rules found.
No public exploits indexed.
Trendmicro
January Patch Tuesday Repairs Critical MS Defender RCE Bug
blogs_trendmicro·2021-01-13·CVSS 7.8
[HIGH] January Patch Tuesday Repairs Critical MS Defender RCE Bug
Exploits & Vulnerabilities
# January Patch Tuesday Repairs Critical MS Defender RCE Bug
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list.
By: Trend Micro
2021/01/13
Read time: ( words)
Save to Folio
Updated on 1/14/2021 7 p.m. PST to include TippingPoint® Next-Generation Intrusion Prevention System (NGIPS) Protection rules.
Microsoft welcomed the first month of 2021 with a total of 83 security updates — which is an uptick from December’s relatively lighter list. The January Patch Tuesday features 10 Critical and 73 Important patches. All of this month’s Critical patches are meant to fix remote code execution (RCE) vulnerabilities among certain Microsoft products, including Microsoft Defender,
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices
Talos
Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-01-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Jan. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Asheer Malhotra.
Microsoft released its monthly security update Tuesday, disclosing 83 vulnerabilities across its suite of products to kick-off 2021.
There are only 10 critical vulnerabilities as part of this release, while there are two moderate-severity exploits, and the remainder is considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Defender antivirus software, the Microsoft Remote Procedure Call tools and Bluetooth communication with Windows devices. Talos also released a new set of SNORTⓇ rules that provide coverage for some of thes
Zscaler
Zscaler protects against 3 new vulnerabilities for MS-Window
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 3 new vulnerabilities for MS-Window
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2021-01-12
Published