CVE-2021-42309
vulnerability analysis and mitigation

Overview

Microsoft SharePoint Server Remote Code Execution Vulnerability (CVE-2021-42309) was discovered and reported on September 3, 2021. This vulnerability affects Microsoft SharePoint Server installations and was publicly disclosed on January 14, 2022. The vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint Server, requiring authentication for exploitation (ZDI Advisory).

Technical details

The vulnerability exists within the handling of server-side controls in SharePoint Server. The specific flaw occurs when an unsafe server-side control can be instantiated if it is specified as a child of a permitted control. The vulnerability has been assigned a CVSS score of 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating its high severity (ZDI Advisory).

Impact

When successfully exploited, this vulnerability enables attackers to execute code in the context of the service account on the affected SharePoint Server. Given the authentication requirement and the potential for code execution, this vulnerability poses a significant risk to affected systems (ZDI Advisory).

Mitigation and workarounds

Microsoft released a security update to address this vulnerability in December 2021. The fix was included in KB5002045 for SharePoint Server Subscription Edition, along with several other security and non-security related improvements (Microsoft Support).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management