ZDI-23-882: (Pwn2Own) Microsoft SharePoint ValidateTokenIssuer Improper Verification of Cryptographic Signature Authentication Bypass Vulnerability
Published Jun 16, 2023
·Updated
This vulnerability allows remote attackers to bypass authentication on affected installations of Microsoft SharePoint. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Jun 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-882?
The severity of ZDI-23-882 is critical due to its ability to allow unauthorized access to Microsoft SharePoint installations.
2
How do I fix ZDI-23-882?
To fix ZDI-23-882, apply the latest security updates released by Microsoft for SharePoint.
3
What are the potential impacts of ZDI-23-882?
The potential impacts of ZDI-23-882 include unauthorized data access and manipulation within the affected SharePoint environments.
4
Who is affected by ZDI-23-882?
Organizations using vulnerable versions of Microsoft SharePoint are affected by ZDI-23-882.
5
Is authentication required to exploit ZDI-23-882?
No, authentication is not required to exploit ZDI-23-882, making it particularly dangerous.