9.8
CVE-2020-1025
- EPSS 5.85%
- Veröffentlicht 14.07.2020 23:15:11
- Zuletzt bearbeitet 23.02.2026 18:23:01
- Erkennungen
Microsoft Office Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Sharepoint Enterprise Server Version 2016
Microsoft ≫ Sharepoint Foundation Version 2013 Update sp1
Microsoft ≫ Sharepoint Server Version 2019
Microsoft ≫ Skype For Business Version 2015 Update cumulative_update_8
Microsoft ≫ Skype For Business Version 2019 Update cumulative_update_2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.85% | 0.922 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1025