ZDI-24-1206: Microsoft SharePoint SPAutoSerializingObject Deserialization of Untrusted Data Denial-of-Service Vulnerability
Published Sep 10, 2024
·Updated
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2024-43466.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Sep 10, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1206?
The severity of ZDI-24-1206 is rated at a CVSS score of 6.5, indicating a medium risk.
2
How do I fix ZDI-24-1206?
To fix ZDI-24-1206, ensure that you apply the latest security updates and patches provided by Microsoft for SharePoint.
3
What software is affected by ZDI-24-1206?
ZDI-24-1206 affects installations of Microsoft SharePoint.
4
Can ZDI-24-1206 be exploited without authentication?
No, ZDI-24-1206 requires authentication to exploit the vulnerability.
5
What impact does ZDI-24-1206 have on Microsoft SharePoint installations?
ZDI-24-1206 allows attackers to create a denial-of-service condition on affected Microsoft SharePoint installations.