CVE-2018-0944: XSS
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923 and CVE-2018-0947.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0944?
CVE-2018-0944 has a severity rating of critical as it allows for elevation of privilege in affected systems.
How do I fix CVE-2018-0944?
To fix CVE-2018-0944, apply the latest security updates provided by Microsoft for Project Server 2013 SP1 and SharePoint Enterprise Server 2016.
What versions of software are affected by CVE-2018-0944?
CVE-2018-0944 affects Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016.
What type of vulnerability is CVE-2018-0944?
CVE-2018-0944 is classified as an elevation of privilege vulnerability due to improper sanitization of specially crafted web requests.
Can CVE-2018-0944 be exploited remotely?
Yes, CVE-2018-0944 can be exploited remotely by sending crafted web requests to the affected services.