An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access.
To exploit this vulnerability, an attacker would need to modify the token.
The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1025 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: microsoft
Published: 2020-07-14T22:53:56
Updated: 2024-05-28T20:54:51.253Z
Reserved: 2019-11-04T00:00:00
Link: CVE-2020-1025
JSON object: View
NVD Information
Status : Modified
Published: 2020-07-14T23:15:11.447
Modified: 2024-05-28T21:15:22.083
Link: CVE-2020-1025
JSON object: View
Redhat Information
No data.
CWE