CVE-2020-1440: Microsoft SharePoint Server Tampering Vulnerability
<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user.</p> <p>The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.</p>
Other sources
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data, aka 'Microsoft SharePoint Server Tampering Vulnerability'. This CVE ID is unique from CVE-2020-1523.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1440?
CVE-2020-1440 has a severity rating of critical as it allows attackers to tamper with profile data in Microsoft SharePoint Server.
How do I fix CVE-2020-1440?
To fix CVE-2020-1440, you should apply the latest security updates provided by Microsoft for your affected version of SharePoint Server.
Which versions of SharePoint Server are affected by CVE-2020-1440?
CVE-2020-1440 affects Microsoft SharePoint Server 2010 SP2, 2013 SP1, 2016, and 2019.
What type of vulnerability is CVE-2020-1440?
CVE-2020-1440 is categorized as a tampering vulnerability related to improper handling of profile data in SharePoint.
Is CVE-2020-1440 specific to a single product?
No, CVE-2020-1440 affects multiple versions of both SharePoint Server and SharePoint Enterprise Server.