ZDI-23-883: (Pwn2Own) Microsoft SharePoint GenerateProxyAssembly Code Injection Remote Code Execution Vulnerability
Published Jun 16, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Jun 16, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-883?
The severity of ZDI-23-883 is high due to the potential for remote code execution by attackers.
2
How do I fix ZDI-23-883?
To fix ZDI-23-883, apply the latest security patches provided by Microsoft for SharePoint.
3
Who is affected by ZDI-23-883?
Organizations using Microsoft SharePoint are affected by ZDI-23-883.
4
What versions of Microsoft SharePoint are impacted by ZDI-23-883?
ZDI-23-883 affects all installations of Microsoft SharePoint that utilize the vulnerable authentication mechanism.
5
Can ZDI-23-883 be exploited without authentication?
No, ZDI-23-883 requires authentication, but existing authentication mechanisms can be bypassed.