CVE-2023-33165
published 2023-07-11CVE-2023-33165: Microsoft SharePoint Server Security Feature Bypass Vulnerability
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.13%
62.7th percentile
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10400.20008 | 16.0.10400.20008 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.16130.20642 | 16.0.16130.20642 |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_msrc4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8mc3-vjhp-gmh6: Microsoft SharePoint Server Security Feature Bypass Vulnerability
ghsa_unreviewed·2023-07-11
CVE-2023-33165 [HIGH] GHSA-8mc3-vjhp-gmh6: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft
Microsoft SharePoint Server Security Feature Bypass Vulnerability
vendor_msrc·2023-07-11·CVSS 4.3
CVE-2023-33165 [MEDIUM] CWE-200 Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L)? What does that mean for this vulnerability?
The attacker who successfully exploits the vulnerability could download files without the access being logged.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker could bypass the logging of downloaded files.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://www.microsoft.com/dow
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published