← Back

CVE-2020-1025

nvd nist
Published: Jul 14, 2020Modified: Feb 23, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update addresses the vulnerability by modifying how Microsoft SharePoint Server and Skype for Business Server validate tokens.

Affected (6)

5 products
Lync
Sharepoint Enterprise Server
Sharepoint Foundation
Sharepoint Server
Skype For Business
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Version 2013
Version 2016
Version 2013 sp1
Version 2019
Microsoft
Version 2015 cumulative_update_8
Version 2019 cumulative_update_2

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.