SharePoint 2016 Security Vulnerability

Lernout, Matthew 20 Reputation points
2024-03-08T19:38:56.78+00:00

Hi,

We have a SharePoint 2016 server patched with the latest January 2024 cumulative security update.

It is possible to spoof links into redirectpage.aspx requests as outlined in https://msrc.microsoft.com/update-guide/en-us/advisory/CVE-2020-1323

Reproduction steps:

  1. Copy a link similar to /_layouts/15/redirectpage.aspx?target=http://@spoofsite.com&VIEWSTATE=http://@spoofsite.com into a browser and visit.
  2. User is redirected to the spoofed spoofsite.com

There is a security update link on the CVE-2020-1323 page, but the download link is broken. I'm of understanding it should also be included in all cumulative updates. Yet is is vulnerable on our up-to-date patched environment.

How can I patch this issue to prevent the spoof request?

Thanks,

Matt

SharePoint Server
SharePoint Server
A family of Microsoft on-premises document management and storage systems.
2,422 questions
0 comments No comments
{count} votes

Accepted answer
  1. Xyza Xue_MSFT 29,446 Reputation points Microsoft External Staff
    2024-03-11T06:33:04.7866667+00:00

    Hi @Lernout, Matthew ,

    The security update link on the CVE-2020-1323 page has a broken download link. I haven't found a download link that still works either. However, this issue should be included in all cumulative updates. To patch this issue, you should ensure that your SharePoint 2016 server is patched with the latest cumulative security update. If your server is already patched with the latest cumulative security update, then it should be protected against this vulnerability.Given your situation, it's difficult for us to help you solve the problem through the forums, we suggest you raise a support ticket with Microsoft, they have higher access to help you check the cause of the problem. Please go to the website Global Customer Service phone numbers - Microsoft Support) to find related number and call it to create a new Phone Service Request to Microsoft Phone Support team.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.