Vulnerability Description
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923, CVE-2018-0944 and CVE-2018-0947.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Project Server | 2013 |
| Microsoft | Sharepoint Enterprise Server | 2016 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103285Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040513Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0912PatchVendor Advisory
- http://www.securityfocus.com/bid/103285Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040513Third Party AdvisoryVDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0912PatchVendor Advisory
FAQ
What is CVE-2018-0912?
CVE-2018-0912 is a vulnerability with a CVSS score of 8.8 (HIGH). Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft ...
How severe is CVE-2018-0912?
CVE-2018-0912 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-0912?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Project Server, Microsoft Sharepoint Enterprise Server.