ZDI-23-884: (Pwn2Own) Microsoft SharePoint userphoto Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft SharePoint. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-884?
The severity of ZDI-23-884 is classified as high due to its potential for disclosing sensitive information.
How can I fix ZDI-23-884?
To fix ZDI-23-884, ensure that the latest security updates for Microsoft SharePoint are applied.
What type of attacks can be executed using ZDI-23-884?
ZDI-23-884 allows remote attackers to disclose sensitive information by bypassing authentication mechanisms.
Which versions of Microsoft SharePoint are affected by ZDI-23-884?
ZDI-23-884 affects installations of Microsoft SharePoint without specifying particular versions.
Is authentication required to exploit ZDI-23-884?
Yes, although authentication is required, the existing authentication mechanisms can be bypassed.