First published: Wed Jan 10 2018(Updated: )
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0789.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server 2016 | =2013-sp1 | |
Microsoft SharePoint Enterprise Server 2016 | =2016 | |
Microsoft SharePoint Foundation 2013 | =2010-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0790 has a severity rating of important for the affected versions of Microsoft SharePoint.
To fix CVE-2018-0790, apply the security update provided by Microsoft for the respective SharePoint version.
CVE-2018-0790 affects Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2013 SP1, and SharePoint Server 2016.
CVE-2018-0790 is an elevation of privilege vulnerability that occurs due to improper handling of web requests.
Yes, CVE-2018-0790 can allow an attacker to gain elevated privileges within the SharePoint environment.