CVE-2023-23395
published 2023-03-14CVE-2023-23395: Microsoft SharePoint Server Spoofing Vulnerability
PriorityP411low3.1CVSS 3.1
AVNACHPRNUIRSUCNILAN
EPSS
0.60%
45.3th percentile
Microsoft SharePoint Server Spoofing Vulnerability
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | >= 15.0.0 < 15.0.5537.1000 | 15.0.5537.1000 |
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5387.1000 | 16.0.5387.1000 |
| microsoft | microsoft_sharepoint_foundation_2013_service_pack_1 | >= 15.0.0 < 15.0.5537.1000 | 15.0.5537.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10396.20000 | 16.0.10396.20000 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.16130.20166 | 16.0.16130.20166 |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_foundation_2013_service_pack_1 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_msrc3.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability
vendor_msrc·2023-03-14·CVSS 3.1
CVE-2023-23395 [LOW] CWE-601 Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
FAQ: I am running SharePoint Foundation 2013 Service Pack 1. Do I need to install all the updates that are listed for SharePoint Foundation 2013 Service Pack 1 ?
Yes, customers running SharePoint Foundation 2013 Service Pack 1 should install both of the security updates. The updates can be installed in any order.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to gather information specific to the environment of the targeted component.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
T
GHSA
GHSA-rr5p-5r8c-rvv5: Microsoft SharePoint Server Spoofing Vulnerability
ghsa_unreviewed·2023-03-14
CVE-2023-23395 [LOW] GHSA-rr5p-5r8c-rvv5: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published