CVE-2019-0668: XSS
Published Mar 5, 2019
·Updated
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Affected Software
2 affected components
Microsoft SharePoint Enterprise Server=2013-sp1
Microsoft SharePoint Enterprise Server=2016
Remediation
Event History
Mar 5, 2019
CVE Published
11:29 PM
Mar 6, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0668?
CVE-2019-0668 has a severity rating of important according to Microsoft.
2
How do I fix CVE-2019-0668?
To fix CVE-2019-0668, apply the security update provided by Microsoft for the affected SharePoint Server versions.
3
Which versions of SharePoint are affected by CVE-2019-0668?
CVE-2019-0668 affects Microsoft SharePoint Enterprise Server 2013 SP1 and 2016.
4
What does the CVE-2019-0668 vulnerability allow an attacker to do?
CVE-2019-0668 allows an attacker to elevate their privileges on the affected SharePoint server.
5
Is there a workaround for CVE-2019-0668?
There are no known workarounds for CVE-2019-0668 other than applying the security patches.