CVE-2022-41038: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-38053, CVE-2022-41036, CVE-2022-41037.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.0.5493.1000Patch KB5002284 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5365.1000Patch KB5002287 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.15601.20158Patch KB5002290 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10391.20000Patch KB5002278
Event History
Frequently Asked Questions
What is CVE-2022-41038?
CVE-2022-41038 is a Microsoft SharePoint Server Remote Code Execution Vulnerability.
What is the severity of CVE-2022-41038?
The severity of CVE-2022-41038 is high with a CVSS score of 8.8.
Which software versions are affected by CVE-2022-41038?
Microsoft SharePoint Foundation 2013 SP1, Microsoft SharePoint Server, Microsoft SharePoint Server 2013 SP1, Microsoft SharePoint Server 2016, and Microsoft SharePoint Server 2019 are affected by CVE-2022-41038.
How can I fix CVE-2022-41038?
To fix CVE-2022-41038, it is recommended to apply the latest security updates provided by Microsoft.
Where can I find more information about CVE-2022-41038?
You can find more information about CVE-2022-41038 on the Microsoft Security Guidance Advisory page at https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41038.