First published: Thu May 21 2020(Updated: )
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1023 has a severity rating of Critical.
To fix CVE-2020-1023, users should apply the latest security updates provided by Microsoft for affected versions of SharePoint.
CVE-2020-1023 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, and SharePoint Server 2019.
If exploited, CVE-2020-1023 could allow an attacker to execute arbitrary code on the affected SharePoint server.
CVE-2020-1023 was reported in January 2020.