CVE-2018-8635 is an elevation of privilege vulnerability in Microsoft SharePoint Server that arises from improper sanitization of specially crafted authentication requests. This flaw impacts Microsoft SharePoint Server and SharePoint Enterprise Server, allowing an authenticated attacker to gain elevated privileges. With a CVSS score of 8.8 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity and can lead to high impacts on confidentiality, integrity, and availability. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it was reportedly exploited as a zero-day, as indicated by media coverage and its inclusion in Microsoft's December 2018 Patch Tuesday. Community discussion and media coverage suggest moderate attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2013:sp1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
2010CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2010:sp2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.