CVE-2022-38009: Microsoft SharePoint Server Remote Code Execution Vulnerability
Published Sep 13, 2022
·Updated
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected Software
10 affected componentsFixes available
Microsoft SharePoint Foundation 2013
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server 2013
Microsoft SharePoint Server 2019
Microsoft SharePoint Enterprise Server=2013-sp1
Microsoft SharePoint Enterprise Server=2016
Microsoft SharePoint Foundation=2013-sp1
Microsoft SharePoint Server
Microsoft SharePoint Server=2019
Microsoft SharePoint Enterprise Server 2016
Event History
Sep 13, 2022
CVE Published
07:00 AM
Data Sourced
07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2022-38009?
CVE-2022-38009 is a remote code execution vulnerability in Microsoft SharePoint Server.
2
How does CVE-2022-38009 affect Microsoft SharePoint Server?
CVE-2022-38009 affects Microsoft SharePoint Server by allowing remote attackers to execute arbitrary code on the server.
3
What is the severity of CVE-2022-38009?
CVE-2022-38009 has a severity rating of 8.8 (high).
4
Which versions of Microsoft SharePoint Server are affected by CVE-2022-38009?
CVE-2022-38009 affects SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Server Subscription Edition, and SharePoint Server 2019.
5
How can I fix CVE-2022-38009?
To fix CVE-2022-38009, apply the relevant patches provided by Microsoft for the affected versions of SharePoint Server.