Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2023-28288

Severity
8.1HIGH
EPSS
8.0%
top 7.93%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 11
Latest updateJun 26

Description

Microsoft SharePoint Server Spoofing Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages7 packages

CVEListV5microsoft/microsoft_sharepoint_server_201916.0.016.0.10397.20002
CVEListV5microsoft/microsoft_sharepoint_enterprise_server_201616.0.016.0.5391.1000
CVEListV5microsoft/microsoft_sharepoint_server_subscription_edition16.0.016.0.16130.20314
NVDmicrosoft/sharepoint_server2013, 2016, 2019+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vpjm-mmm2-rqq5: Microsoft SharePoint Server Spoofing Vulnerability2023-04-11
CVEList
Microsoft SharePoint Server Spoofing Vulnerability2023-04-11

💥Exploits & PoCs

1
Exploit-DB
Microsoft SharePoint Enterprise Server 2016 - Spoofing2023-06-26

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Server Spoofing Vulnerability2023-04-11