CVE-2022-24472
published 2022-04-15CVE-2022-24472: Microsoft SharePoint Server Spoofing Vulnerability
PriorityP429medium5.7CVSS 3.1
AVNACLPRLUIRSUCNIHAN
EPSS
1.73%
75.2th percentile
Microsoft SharePoint Server Spoofing Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5305.1000 | 16.0.5305.1000 |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < 15.0.5441.1000 | 15.0.5441.1000 |
| microsoft | microsoft_sharepoint_server_2016 | >= 16.0.0.0 < 16.0.5305.1000 | 16.0.5305.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10385.20001 | 16.0.10385.20001 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.14931.20196 | 16.0.14931.20196 |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rgrf-mwcx-w9r5: Microsoft SharePoint Server Spoofing Vulnerability
ghsa_unreviewed·2022-04-16
CVE-2022-24472 [HIGH] GHSA-rgrf-mwcx-w9r5: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability.
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability
vendor_msrc·2022-04-12·CVSS 8.0
CVE-2022-24472 [HIGH] Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
FAQ: How could an attacker exploit this vulnerability?
A standard user who has been authenticated in the domain could potentially use this vulnerability to send malicious content in SIP Address field which would allow
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-15
Published