VulnerabilityModified
CVE-2018-0869
SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".
MEDIUM 5.4EPSS 2.19%
Does this matter?
Lower severity and a low EPSS score (2.19%). Track it; it rarely justifies an emergency change on its own.
Description
SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.19% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/sharepoint enterprise server
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/102963Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040376Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0869Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102963Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040376Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0869Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.