CVE-2021-34520: Microsoft SharePoint SetVariableActivity Deserialization of Untrusted Data Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the Microsoft.SharePoint.WorkflowActions.SetVariableActivity class. A crafted SetVariableActivity element can result in instantiation of an arbitrary .NET type. An attacker can leverage this vulnerability to execute code in the context of the web service account.
— ZDI
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-34520?
CVE-2021-34520 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint.
How severe is CVE-2021-34520?
CVE-2021-34520 has a severity rating of 8.8 out of 10, indicating a high level of risk.
What is the affected software by CVE-2021-34520?
Microsoft SharePoint versions 2013 SP1, 2016, and 2019 are affected by CVE-2021-34520.
What is the specific flaw in CVE-2021-34520?
The specific flaw in CVE-2021-34520 exists within the Microsoft.SharePoint.WorkflowActions.SetVariableActivity class.
How can I exploit CVE-2021-34520?
Authentication is required to exploit CVE-2021-34520.
Are there any references for CVE-2021-34520?
Yes, you can find more information about CVE-2021-34520 at the following references: [Reference 1](https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34520), [Reference 2](https://www.zerodayinitiative.com/advisories/ZDI-21-828/), [Reference 3](https://msrc.microsoft.com/update-guide/en-us/vulnerability/CVE-2021-34520).