First published: Thu May 21 2020(Updated: )
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Foundation | =2013-sp1 | |
Microsoft SharePoint Server | =2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-1024 has a severity rating of critical according to Microsoft's vulnerability classification.
To fix CVE-2020-1024, you should apply the latest security updates provided by Microsoft for affected SharePoint products.
CVE-2020-1024 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, and SharePoint Server 2019.
CVE-2020-1024 is classified as a remote code execution vulnerability that allows an attacker to execute arbitrary code.
Yes, CVE-2020-1024 can be exploited easily due to the failure to properly check source markup in application packages.