CVE-2023-33142
published 2023-06-14CVE-2023-33142: Microsoft SharePoint Server Elevation of Privilege Vulnerability
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.02%
59.4th percentile
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10399.20005 | 16.0.10399.20005 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.16130.20548 | 16.0.16130.20548 |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
vendor_msrc6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft SharePoint Server Elevation of Privilege Vulnerability
vendor_msrc·2023-06-13·CVSS 6.5
CVE-2023-33142 [MEDIUM] CWE-285 Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited the vulnerability?
An attacker who successfully exploited the vulnerability would be able to create a list or document library in the targeted SharePoint site.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to a major loss of integrity (I:H) but no loss of confidentiality (C:N), or have any effect on availability (A:N). How could an attacker affect the SharePoint site?
An attacker who successfully exploited this vulnerability could create a list or document library in the targeted SharePoint site thus affecting the integrity. However, an attacker could not edit or delete a list or document library fro
GHSA
GHSA-cxh6-r76c-598v: Microsoft SharePoint Server Elevation of Privilege Vulnerability
ghsa_unreviewed·2023-06-14
CVE-2023-33142 [MEDIUM] GHSA-cxh6-r76c-598v: Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-14
Published