ZDI-CAN-20375: ZDI-23-571: Microsoft SharePoint AdRotator Improper Input Validation NTLM Relay Vulnerability
Published May 10, 2023
·Updated
This vulnerability allows remote attackers to relay NTLM credentials on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability.
Affected Software
1 affected component
Microsoft SharePoint
Event History
May 10, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-20375?
ZDI-CAN-20375 has been classified as a critical vulnerability due to the potential for remote credential relaying.
2
How do I fix ZDI-CAN-20375?
To mitigate ZDI-CAN-20375, ensure that you apply the latest security updates for Microsoft SharePoint.
3
What impact does ZDI-CAN-20375 have on Microsoft SharePoint?
ZDI-CAN-20375 allows remote attackers to relay NTLM credentials, potentially compromising user accounts.
4
Is authentication required to exploit ZDI-CAN-20375?
Yes, authentication is required to exploit the ZDI-CAN-20375 vulnerability.
5
Which versions of Microsoft SharePoint are affected by ZDI-CAN-20375?
ZDI-CAN-20375 affects installations of Microsoft SharePoint without proper security updates.