CVE-2020-1025
Microsoft Office Elevation of Privilege Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access.
To exploit this vulnerability, an attacker would need to modify the token.
The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
Se presenta una vulnerabilidad de elevación de privilegios cuando Microsoft SharePoint Server y Skype for Business Server manejan inapropiadamente la comprobación de del token de OAuth, también se conoce como "Microsoft Office Elevation of Privilege Vulnerability"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-11-04 CVE Reserved
- 2020-07-14 CVE Published
- 2024-02-09 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1025 | 2024-05-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Microsoft Search vendor "Microsoft" | Lync Search vendor "Microsoft" for product "Lync" | 2013 Search vendor "Microsoft" for product "Lync" and version "2013" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Enterprise Server Search vendor "Microsoft" for product "Sharepoint Enterprise Server" | 2016 Search vendor "Microsoft" for product "Sharepoint Enterprise Server" and version "2016" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Foundation Search vendor "Microsoft" for product "Sharepoint Foundation" | 2013 Search vendor "Microsoft" for product "Sharepoint Foundation" and version "2013" | sp1 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Sharepoint Server Search vendor "Microsoft" for product "Sharepoint Server" | 2019 Search vendor "Microsoft" for product "Sharepoint Server" and version "2019" | - |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Skype For Business Search vendor "Microsoft" for product "Skype For Business" | 2015 Search vendor "Microsoft" for product "Skype For Business" and version "2015" | cumulative_update_8 |
Affected
| ||||||
Microsoft Search vendor "Microsoft" | Skype For Business Search vendor "Microsoft" for product "Skype For Business" | 2019 Search vendor "Microsoft" for product "Skype For Business" and version "2019" | cumulative_update_2 |
Affected
|