ZDI-23-546: Microsoft SharePoint Chart Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint Server. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-546?
The severity of ZDI-23-546 is rated as 51, indicating a significant risk associated with potential remote code execution.
How do I fix ZDI-23-546?
To fix ZDI-23-546, ensure that your Microsoft SharePoint Server is updated to the latest security patch provided by Microsoft.
Who is affected by ZDI-23-546?
Organizations using Microsoft SharePoint Server that have not implemented the necessary security updates are at risk from ZDI-23-546.
What type of attack does ZDI-23-546 enable?
ZDI-23-546 enables remote attackers to execute arbitrary code on vulnerable Microsoft SharePoint Server installations.
Is authentication required to exploit ZDI-23-546?
Yes, authentication is required to exploit the ZDI-23-546 vulnerability on affected Microsoft SharePoint Server installations.