CVE-2020-16953

Description

An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. To exploit the vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The security update addresses the vulnerability by correcting how Microsoft SharePoint Server handles objects in memory.

Risk Information

Base Score
6.4
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
23.356

Associated Vulnerability

VulnerabilityOS Platform
Microsoft Office SharePoint XSS Vulnerability for Microsoft SharePoint Foundation 2013 (KB4486694)Windows
Microsoft SharePoint Information Disclosure Vulnerability for Microsoft SharePoint Foundation 2010 (KB4486708)Windows
Microsoft SharePoint Information Disclosure Vulnerability for Microsoft SharePoint Enterprise Server 2016 (KB4486677)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-30132Security Update for Microsoft SharePoint Foundation 2013 (KB4486694)
PATCH-30139Security Update for Microsoft SharePoint Enterprise Server 2016 (KB4486677)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234