CVE-2021-26420
published 2021-06-08CVE-2021-26420: Microsoft SharePoint Server Remote Code Execution Vulnerability
PriorityP357high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.96%
85.7th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5173.1000 | 16.0.5173.1000 |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < 15.0.5353.1000 | 15.0.5353.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10375.20000 | 16.0.10375.20000 |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hvcm-v277-w2xw: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31966
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2021-31963 [HIGH] GHSA-hvcm-v277-w2xw: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31966.
GHSA
GHSA-988w-q87v-mrx5: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31963
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2021-31966 [HIGH] GHSA-988w-q87v-mrx5: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31963
Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-26420, CVE-2021-31963.
GHSA
GHSA-fgqv-x4rv-8256: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31963, CVE-2021-31966
ghsa_unreviewed·2022-05-24·CVSS 7.1
CVE-2021-26420 [HIGH] GHSA-fgqv-x4rv-8256: Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31963, CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-31963, CVE-2021-31966.
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2021-06-08·CVSS 7.1
CVE-2021-26420 [HIGH] Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=29e155c6-6f3d-4f43-b08b-2f7976876511
Reference: https://support.microsoft.com/help/5001946
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=b009b05d-86c1-404d-947d-759d1a60ae12
Reference: https://support.microsoft.com/help/5001944
Reference: https://www.microsoft.com/downloads/details.aspx?familyid=a8ba0918-5776-4ba8-98dc-4cb71653ee0d
Reference: https://support.microsoft
No detection rules found.
No public exploits indexed.
Trendmicro
CVE-2021-26420: Remote Code Execution in SharePoint
blogs_trendmicro·2021-10-06·CVSS 7.1
CVE-2021-26420 [HIGH] CVE-2021-26420: Remote Code Execution in SharePoint
## CVE-2021-26420: Remote Code Execution in SharePoint via Workflow Compilation
Learn remote code execution in SharePoint with workflows.
By: Zero Day Initiative Oct 06, 2021 Read time: ( words)
Save to Folio
In June of 2021, Microsoft released a patch to correct CVE-2021-26420 – a remote code execution bug in the supported versions of Microsoft SharePoint Server. This bug was reported to the ZDI program by an anonymous researcher and is also known as ZDI-21-755 . This blog takes a deeper look at the root cause of this vulnerability.
Before this patch being made available, this vulnerability could be used by an authenticated user to execute arbitrary .NET code on the server in the context and permissions of service account of SharePoint web application. For successful attack, the atta
Trendmicro
CVE-2021-26420: Remote Code Execution in SharePoint
blogs_trendmicro·2021-10-06·CVSS 7.1
CVE-2021-26420 [HIGH] CVE-2021-26420: Remote Code Execution in SharePoint
# CVE-2021-26420: Remote Code Execution in SharePoint via Workflow Compilation
Learn remote code execution in SharePoint with workflows.
By: Zero Day Initiative
2021/10/06
Read time: ( words)
Save to Folio
In June of 2021, Microsoft released a patch to correct CVE-2021-26420 – a remote code execution bug in the supported versions of Microsoft SharePoint Server. This bug was reported to the ZDI program by an anonymous researcher and is also known as ZDI-21-755. This blog takes a deeper look at the root cause of this vulnerability.
Before this patch being made available, this vulnerability could be used by an authenticated user to execute arbitrary .NET code on the server in the context and permissions of service account of SharePoint web application. For successful attack, the attacke
Trendmicro
CVE-2021-26420: Remote Code Execution in SharePoint
blogs_trendmicro·2021-10-06·CVSS 7.1
CVE-2021-26420 [HIGH] CVE-2021-26420: Remote Code Execution in SharePoint
## CVE-2021-26420: Remote Code Execution in SharePoint via Workflow Compilation
Learn remote code execution in SharePoint with workflows.
By: Zero Day Initiative 2021/10/06 Read time: ( words)
Save to Folio
In June of 2021, Microsoft released a patch to correct CVE-2021-26420 – a remote code execution bug in the supported versions of Microsoft SharePoint Server. This bug was reported to the ZDI program by an anonymous researcher and is also known as ZDI-21-755 . This blog takes a deeper look at the root cause of this vulnerability.
Before this patch being made available, this vulnerability could be used by an authenticated user to execute arbitrary .NET code on the server in the context and permissions of service account of SharePoint web application. For successful attack, the attack
Qualys
Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
blogs_qualys·2021-06-08·CVSS 5.2
CVE-2021-31985 [MEDIUM] Microsoft & Adobe Patch Tuesday (June 2021) – Microsoft 50 Vulnerabilities with 5 Critical, Adobe 21 Critical Vulnerabilities
## Microsoft Patch Tuesday – June 2021
Microsoft patched 50 CVEs in their June 2021 Patch Tuesday release, and five of them are rated as critical severity. Six have applicable exploits.
## Critical Microsoft Vulnerabilities Patched
CVE-2021-31985 – Microsoft Defender Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in its Defender product (CVE-2021-31985). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 7.8 by the vendor.
CVE-2021-31959 – Scripting Engine Memory Corruption Vulnerability
Microsoft released patches addressing a critical memory corruption vulnerability in the Chakra JScript scripting engine. This vulnerability impacts Windows RT, Windows 7, Windows 8, Windows 10, Windows Server
2021-06-08
Published