First published: Wed Mar 14 2018(Updated: )
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923 and CVE-2018-0947.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Project Server | =2013-sp1 | |
Microsoft SharePoint Enterprise Server 2016 | =2016 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0944 has a severity rating of critical as it allows for elevation of privilege in affected systems.
To fix CVE-2018-0944, apply the latest security updates provided by Microsoft for Project Server 2013 SP1 and SharePoint Enterprise Server 2016.
CVE-2018-0944 affects Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016.
CVE-2018-0944 is classified as an elevation of privilege vulnerability due to improper sanitization of specially crafted web requests.
Yes, CVE-2018-0944 can be exploited remotely by sending crafted web requests to the affected services.