SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Microsoft의 SharePoint 결함이 인증된 원격 코드 실행을 가능하게 하였습니다.
Microsoft는 SharePoint Server의 취약점을 초기에는 스푸핑 결함으로 분류하였으나, 이 결함이 실제로는 인증된 원격 코드 실행을 가능하게 한다고 발표했습니다. 이 취약점(CVE-2026-65660)은 SharePoint Server 2016, 2019 및 Subscription Edition에 영향을 미치며, 이에 대한 패치도 제공되었습니다. Cyber Security 연구원 Dinh Ho Anh Khoa가 자세한 기술 정보를 공개했습니다.
A SharePoint flaw initially classified by Microsoft as spoofing enables authenticated remote code execution.
Microsoft initially classified a vulnerability in SharePoint Server as a spoofing flaw; however, it actually enables authenticated remote code execution. This vulnerability, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been released to address this issue, as detailed by cyber security researcher Dinh Ho Anh Khoa.