Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sharepoint_enterprise_server | Microsoft | 2016 (including) | 2016 (including) |
Sharepoint_server | Microsoft | * | 16.0.18526.20396 (excluding) |
Sharepoint_server | Microsoft | 2019 (including) | 2019 (including) |