CVE-2022-21987: Microsoft SharePoint Server Spoofing Vulnerability
Published Feb 8, 2022
·Updated
Microsoft SharePoint Server Spoofing Vulnerability
Affected Software
8 affected componentsFixes available
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server 2013
Microsoft SharePoint Enterprise Server=2016
Microsoft SharePoint Foundation=2013-sp1
Microsoft SharePoint Server
Microsoft SharePoint Server=2019
Microsoft SharePoint Enterprise Server 2016
Event History
Feb 8, 2022
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Description
Feb 9, 2022
CVE Published
via MITRE·04:36 PM
Data Sourced
via MITRE·04:36 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-21987?
CVE-2022-21987 is a spoofing vulnerability in Microsoft SharePoint Server.
2
Which versions of SharePoint Server are affected by CVE-2022-21987?
SharePoint Server 2019, SharePoint Enterprise Server 2013, SharePoint Enterprise Server 2016, and SharePoint Server Subscription Edition are affected.
3
What is the severity of CVE-2022-21987?
The severity of CVE-2022-21987 is high with a CVSS score of 8.
4
How can I fix CVE-2022-21987?
Apply the relevant patches provided by Microsoft or follow the remediation steps mentioned in the Microsoft support articles for the affected SharePoint Server versions.