Get a Pentest and security assessment of your IT network.

Cyber Security

Critical SharePoint flaw dissected, RCE details now available

Details are now available for exploiting a critical security vulnerability that affects Microsoft SharePoint, increasing the risk of attacks on unpatched systems. The flaw received the tracking number CVE-2020-1147 (severity 9.8 out of 10) and also impacts Visual Studio.NET Framework and Visual Studio. Microsoft released a fix in this month’s rollout of security updates. A low-privileged user can leverage it to run arbitrary code remotely on a target SharePoint server. The bug is a failure to check the source markup of the XML file input, allowing an attacker to run code.

Source: https://www.bleepingcomputer.com/news/security/critical-sharepoint-flaw-dissected-rce-details-now-available/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security