Blog | G5 Cyber Security

Microsoft issues an out-of-band update to address SharePoint information disclosure flaw

Microsoft issues out-of-band update to address SharePoint flaw, tracked as CVE-2019-1491, that could be exploited to obtain sensitive information. The flaw was reported by Saif ElSherei from the Microsoft Research Centers Vulnerabilities and Mitigations Team. An attacker who exploited this vulnerability could read arbitrary files on the server, reads advisory published by Microsoft. To exploit the vulnerability, an attacker would need to send a specially crafted request to a susceptible SharePoint Server instance. The update addresses the vulnerability by changing how the affected APIs process requests.”]

Source: https://securityaffairs.co/wordpress/95345/hacking/sharepoint-flaw-patch.html

Exit mobile version