CVE-2021-31963 is a critical Remote Code Execution vulnerability affecting Microsoft SharePoint Server and SharePoint Foundation. With a CVSS score of 8.8, it allows an authenticated attacker to execute arbitrary code remotely over the network with low attack complexity, leading to high impact on confidentiality, integrity, and availability. While not listed in CISA KEV, its high EPSS score and significant media coverage (4 articles) indicate considerable community attention. Currently, there is no public exploit code available in Metasploit, Nuclei, or ExploitDB, and it is not identified as actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:* | ||
2013CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2013:sp1:*:*:enterprise:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.