SharePoint Improper Input Validation Vulnerability - CVE-2020-1025 - Vulnerability Database

SharePoint Improper Input Validation Vulnerability - CVE-2020-1025

Critical
Reference: CVE-2020-1025
Title: SharePoint Improper Input Validation Vulnerability
Overview:

An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.