Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sharepoint_server | Microsoft | * | 16.0.18526.20286 (excluding) |
Sharepoint_server | Microsoft | 2016 (including) | 2016 (including) |
Sharepoint_server | Microsoft | 2019 (including) | 2019 (including) |