First published: Wed Jan 10 2018(Updated: )
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server 2016 | =2013-sp1 | |
Microsoft SharePoint Enterprise Server 2016 | =2016 | |
Microsoft SharePoint Server 2010 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0789 has a severity rating of Important, indicating a significant risk of elevation of privilege.
To fix CVE-2018-0789, apply the latest security updates provided by Microsoft for affected SharePoint software versions.
CVE-2018-0789 affects Microsoft SharePoint Foundation 2010, SharePoint Server 2013, and SharePoint Server 2016.
CVE-2018-0789 is classified as an elevation of privilege vulnerability affecting SharePoint.
Yes, CVE-2018-0789 can potentially be exploited remotely if an attacker has the ability to send crafted web requests.