Jul 2020: Microsoft Office Elevation of Privilege Vulnerability
CVE-2020-1025 Published on July 14, 2020

Microsoft Office Elevation of Privilege Vulnerability
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

NVD


Products Associated with CVE-2020-1025

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-1025 are published in these products:

 
 
 
 
 

Affected Versions

Microsoft Skype for Business Server 2019 CU2: Microsoft Skype for Business Server 2015 CU 8: Microsoft Lync Server 2013: Microsoft SharePoint Enterprise Server 2016: Microsoft SharePoint Server 2019: Microsoft SharePoint Foundation 2013 Service Pack 1:

Exploit Probability

EPSS
13.80%
Percentile
94.13%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.