CVE-2021-42309: Microsoft SharePoint Server-Side Control Improper Input Validation Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of server-side controls. An unsafe server-side control can be instantiated if it is specified as a child of a permitted control. An attacker can leverage this vulnerability to execute code in the context of the service account.
— ZDI
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42309?
The severity of CVE-2021-42309 is high.
How does CVE-2021-42309 affect Microsoft SharePoint?
CVE-2021-42309 allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint.
What authentication is required to exploit CVE-2021-42309?
Authentication is required to exploit CVE-2021-42309.
How can I fix CVE-2021-42309 on Microsoft SharePoint Server 2019?
To fix CVE-2021-42309 on Microsoft SharePoint Server 2019, apply the patch provided by Microsoft: [url].
How can I fix CVE-2021-42309 on Microsoft SharePoint Foundation 2013?
To fix CVE-2021-42309 on Microsoft SharePoint Foundation 2013, apply the patch provided by Microsoft: [url].