CVE-2021-40487

Microsoft SharePoint Server Remote Code Execution Vulnerability
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

History

28 Feb 2025, 21:15

Type Values Removed Values Added
CWE CWE-94

21 Nov 2024, 06:24

Type Values Removed Values Added
References () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40487 - Patch, Vendor Advisory () https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40487 - Patch, Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-21-1225/ - Third Party Advisory, VDB Entry () https://www.zerodayinitiative.com/advisories/ZDI-21-1225/ - Third Party Advisory, VDB Entry

01 Aug 2023, 23:15

Type Values Removed Values Added
Summary Microsoft SharePoint Server Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41344. Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS v2 : 6.5
v3 : 8.8
v2 : 6.5
v3 : 8.1

04 Nov 2021, 12:36

Type Values Removed Values Added
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-1225/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-1225/ - Third Party Advisory, VDB Entry

21 Oct 2021, 09:15

Type Values Removed Values Added
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-1225/ -

19 Oct 2021, 15:47

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sharepoint_foundation:2013:sp1:*:*:*:*:*:*
References (MISC) https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40487 - (MISC) https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40487 - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8

13 Oct 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-13 01:15

Updated : 2025-02-28 21:15


NVD link : CVE-2021-40487

Mitre link : CVE-2021-40487

CVE.ORG link : CVE-2021-40487


JSON object : View

Products Affected

microsoft

  • sharepoint_enterprise_server
  • sharepoint_foundation
  • sharepoint_server
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')