CVE-2021-38652: Microsoft SharePoint Server Spoofing Vulnerability
Published Sep 14, 2021
·Updated
Microsoft SharePoint Server Spoofing Vulnerability
Affected Software
4 affected componentsFixes available
Microsoft SharePoint Enterprise Server=2016
Microsoft SharePoint Foundation=2013-sp1
Microsoft SharePoint Foundation 2013<5381.1000
5381.1000
Microsoft SharePoint Enterprise Server 2016<5215.1000
5215.1000
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5381.1000Patch KB5002024 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5215.1000Patch KB5002020
Event History
Sep 14, 2021
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
Updated
via Microsoft·02:00 PM
Affected Software
Sep 15, 2021
CVE Published
via MITRE·11:24 AM
Data Sourced
via MITRE·11:24 AM
DescriptionSeverity
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-38652?
CVE-2021-38652 is a spoofing vulnerability in Microsoft SharePoint Server.
2
How severe is CVE-2021-38652?
CVE-2021-38652 has a severity rating of low.
3
Which versions of Microsoft SharePoint Server are affected by CVE-2021-38652?
Microsoft SharePoint Enterprise Server 2016 and Microsoft SharePoint Foundation 2013 with SP1 are affected by CVE-2021-38652.
4
How can I fix CVE-2021-38652?
Apply the necessary security updates provided by Microsoft to fix CVE-2021-38652.
5
Where can I find more information about CVE-2021-38652?
You can find more information about CVE-2021-38652 on the Microsoft Security Guidance Advisory page.