CVE-2018-0789 is an elevation of privilege vulnerability affecting Microsoft SharePoint Foundation 2010, SharePoint Server 2013, and SharePoint Server 2016, stemming from improper handling of web requests. With a CVSS score of 8.8 (High), it allows an authenticated attacker to achieve high confidentiality, integrity, and availability impact over the network with low attack complexity. While not listed in CISA's KEV catalog, its EPSS score of 0.21719 indicates a higher-than-average likelihood of exploitation. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and community discussion and media coverage are minimal, suggesting it is not widely exploited in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.