ZDI-23-571: Microsoft SharePoint AdRotator Improper Input Validation NTLM Relay Vulnerability
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-571?
The severity of ZDI-23-571 is classified as high due to the potential for unauthorized NTLM credential relay.
How do I fix ZDI-23-571?
To fix ZDI-23-571, ensure that the affected Microsoft SharePoint installations are updated to the latest security patches provided by Microsoft.
What type of authentication is required to exploit ZDI-23-571?
Exploitation of ZDI-23-571 requires valid authentication credentials to successfully relay NTLM authentication.
Who can exploit ZDI-23-571?
Remote attackers with valid authentication can exploit ZDI-23-571 to relay NTLM credentials.
Which software is affected by ZDI-23-571?
ZDI-23-571 affects Microsoft SharePoint installations, particularly versions that have not been updated to mitigate this vulnerability.