ZDI-CAN-20749: ZDI-23-883: (Pwn2Own) Microsoft SharePoint GenerateProxyAssembly Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-20749?
The severity of ZDI-CAN-20749 is considered critical due to the potential for remote code execution.
How do I fix ZDI-CAN-20749?
To fix ZDI-CAN-20749, apply the latest security updates provided by Microsoft for SharePoint installations.
What types of installations are affected by ZDI-CAN-20749?
ZDI-CAN-20749 affects Microsoft SharePoint installations that are vulnerable to authentication bypass.
Can ZDI-CAN-20749 be exploited without authentication?
No, ZDI-CAN-20749 requires authentication; however, the vulnerability allows attackers to bypass existing authentication mechanisms.
What are the potential impacts of ZDI-CAN-20749?
The potential impacts of ZDI-CAN-20749 include unauthorized access and arbitrary code execution on affected SharePoint systems.