Original Release Date: 10/22/2020
The National Cyber Security Centre (NCSC) issued a security alert regarding a serious remote code execution (RCE) vulnerability in Microsoft SharePoint. Vulnerability CVE-2020-16952 may allow an attacker to execute arbitrary code remotely, potentially posing a higher risk for multi-tenant environments. A proof of concept has been released for the flaw, increasing the likelihood of exploitation. Affected versions include Foundation 2013 Service Pack 1, Enterprise Server 2016, and Server 2019. SharePoint Online as part of Office 365 is not affected.
The NJCCIC recommends users of affected versions apply the October 2020 Microsoft SharePoint update immediately. Additional information can be found in the HIPAA Journal article.