CVE-2021-36940: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5371.1000Patch KB4011600 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5200.1000Patch KB5002002 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10377.20000Patch KB5002000
Event History
Frequently Asked Questions
What is CVE-2021-36940?
CVE-2021-36940 is a spoofing vulnerability in Microsoft SharePoint Server.
How severe is CVE-2021-36940?
CVE-2021-36940 has a severity rating of medium, with a score of 4.3.
Which versions of Microsoft SharePoint Server are affected by CVE-2021-36940?
Microsoft SharePoint Enterprise Server 2013 SP1, 2016, and SharePoint Server 2019 are affected by CVE-2021-36940.
What is the impact of CVE-2021-36940?
CVE-2021-36940 allows an attacker to spoof content and execute phishing attacks.
Is there a fix available for CVE-2021-36940?
Yes, Microsoft has released security updates to address CVE-2021-36940. It is recommended to apply the latest updates as soon as possible.