CVE-2020-0976: Medium severity microsoft sharepoint enterprise server 2016 vulnerability
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-0976?
CVE-2020-0976 is classified as a spoofing vulnerability which can potentially allow an attacker to impersonate a user.
How do I fix CVE-2020-0976?
To mitigate CVE-2020-0976, apply the latest security updates provided by Microsoft for SharePoint Server 2016 and SharePoint Foundation 2013 SP1.
Which software versions are affected by CVE-2020-0976?
CVE-2020-0976 affects Microsoft SharePoint Enterprise Server 2016 and Microsoft SharePoint Foundation 2013 SP1.
What kind of attacks can CVE-2020-0976 enable?
CVE-2020-0976 may enable an attacker to craft a malicious web request to manipulate SharePoint functionality.
Is user action required to exploit CVE-2020-0976?
Yes, exploiting CVE-2020-0976 typically requires the user to click on a specially crafted link that triggers the spoofing vulnerability.