ZDI-21-755: Microsoft SharePoint WorkflowCompilerInternal Exposed Dangerous Function Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the System.Workflow.ComponentModel.Compiler.WorkflowCompilerInternal class. This class allows an attacker to specify a path to an arbitrary workflow definition file. An attacker can leverage this vulnerability to execute code in the context of the web service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-21-755?
ZDI-21-755 has been rated as high severity due to its potential for remote code execution.
How do I fix ZDI-21-755?
To mitigate ZDI-21-755, apply the latest security updates provided by Microsoft for SharePoint.
What types of attacks can be executed through ZDI-21-755?
ZDI-21-755 allows remote attackers to execute arbitrary code on compromised SharePoint installations.
Is authentication required to exploit ZDI-21-755?
Yes, authentication is required to exploit the vulnerability identified in ZDI-21-755.
What software is affected by ZDI-21-755?
ZDI-21-755 affects Microsoft SharePoint installations that are not updated with the latest security patches.