ZDI-CAN-16664: ZDI-23-546: Microsoft SharePoint Chart Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published May 4, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint Server. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Microsoft SharePoint Server
Event History
May 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-16664?
ZDI-CAN-16664 has been classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix ZDI-CAN-16664?
To mitigate ZDI-CAN-16664, ensure that your Microsoft SharePoint Server is updated with the latest security patches provided by Microsoft.
3
What systems are affected by ZDI-CAN-16664?
ZDI-CAN-16664 affects Microsoft SharePoint Server 2010 installations.
4
Is authentication required to exploit ZDI-CAN-16664?
Yes, authentication is required for an attacker to exploit the ZDI-CAN-16664 vulnerability.
5
What is the impact of ZDI-CAN-16664 if successfully exploited?
If successfully exploited, ZDI-CAN-16664 allows remote attackers to execute arbitrary code on the affected SharePoint Server.