cbcvebase.
CVE-2022-21837
published 2022-01-11

CVE-2022-21837: Microsoft SharePoint Server Remote Code Execution Vulnerability

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
2.84%
85.1th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability

Affected

11 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5266.100016.0.5266.1000
microsoftmicrosoft_sharepoint_foundation_2013_service_pack_1>= 15.0.0 < 15.0.5415.100015.0.5415.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10382.2000416.0.10382.20004
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.14326.2071416.0.14326.20714
microsoftsharepoint_foundation
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_foundation_2013_service_pack_1
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

snort
SIDs: 40689, 40690, 58859, 58860, 58866 - 58869 and 58870 - 58875
  • Exploitation requires an authenticated attacker with domain access performing RCE on the SharePoint server to elevate to SharePoint admin; monitor for unexpected privilege escalation to SharePoint admin role.
  • ·As of the January 2022 Patch Tuesday disclosure, the vulnerability had not been exploited in the wild and was rated 'Exploitation Less Likely' for both latest and older software releases.
  • ·None of the 126 January 2022 Patch Tuesday vulnerabilities, including CVE-2022-21837, were known to be actively exploited at time of disclosure.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_msrc8.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.