CVE-2022-41036: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41037, CVE-2022-41038.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5493.1000Patch KB5002284 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.15601.20158Patch KB5002290 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5365.1000Patch KB5002287 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10391.20000Patch KB5002278
Event History
Frequently Asked Questions
What is CVE-2022-41036?
CVE-2022-41036 is a remote code execution vulnerability in Microsoft SharePoint Server.
What is the severity of CVE-2022-41036?
CVE-2022-41036 has a severity score of 8.8 out of 10 (high).
Which versions of Microsoft SharePoint Server are affected by CVE-2022-41036?
Microsoft SharePoint Foundation 2013 SP1, Microsoft SharePoint Server (all versions), Microsoft SharePoint Server 2013 SP1, Microsoft SharePoint Server 2016, and Microsoft SharePoint Server 2019 are affected by CVE-2022-41036.
How does CVE-2022-41036 impact the system?
CVE-2022-41036 allows remote attackers to execute arbitrary code on the affected SharePoint Server.
How can I fix CVE-2022-41036?
Apply the latest security updates provided by Microsoft to fix CVE-2022-41036.