Security Advisory
CVE-2020-1523
8.9
HIGH
Vulnerability Description
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.
To exploit the vulnerability, an attacker would need to be authenticated on an affected SharePoint Server. The attacker would then need to send a specially modified request to the server, targeting a specific user.
The security update addresses the vulnerability by modifying how Microsoft SharePoint Server handles profile data.
Published Date
September 11, 2020
Official Source
NIST NVD Advisory