Sceawere

Vulnerability Detail

CVE-2026-63514UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint Deserialization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Enterprise Server 2016
Attack Type
CWE-502: Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-11T17:18:46.213Z",
  "pubdate": "2026-08-11T17:18:46.213Z",
  "executiveSummary": "A deserialization of untrusted data vulnerability exists in Microsoft Office SharePoint, exposing the affected systems to remote code execution risks.\nThe vulnerability allows an authorized remote attacker to execute arbitrary code over the network by supplying specially crafted payloads that are improperly handled during the object deserialization process.\nThis flaw impacts Microsoft Office SharePoint deployments, creating severe risk implications that can lead to complete compromise of the underlying host system, data exfiltration, or lateral movement within the enterprise network.\nExploitation of this security defect requires the attacker to possess valid authorization to interact with the vulnerable SharePoint service, after which the malicious input can be processed to trigger memory corruption or execution flows.\nThe inherent risks associated with unsafe deserialization in enterprise collaboration platforms necessitate immediate remediation through official vendor patches and strict input validation enforcement.",
  "technicalDetails": "The root cause of the vulnerability stems from the insecure handling and deserialization of untrusted data streams within Microsoft Office SharePoint.\nWhen the application reconstructs serialized objects without implementing adequate type safety checks, filtering, or cryptographic integrity verification, malicious payloads can be injected into the data stream.\nThe vulnerable component is responsible for parsing complex object graphs received from network requests processed by the SharePoint infrastructure.\nExploitation occurs when an authenticated attacker constructs a malicious serialized payload designed to leverage gadget chains present within the application runtime classpath or libraries.\nUpon transmission of the payload over the network to the vulnerable SharePoint endpoint, the deserialization mechanism instantiates the malicious object graph.\nDuring the instantiation and property population phase, the embedded gadget chain executes arbitrary methods, leading to remote code execution under the security context of the service account running the SharePoint process.\nThe attack flow proceeds as follows: first, the authorized attacker authenticates to the target SharePoint service; second, the attacker crafts a specialized serialized payload containing the exploit gadget chain; third, the payload is transmitted via the network protocol used by the service; fourth, the application deserializes the input without validation; and finally, the underlying system executes the resulting arbitrary code.\nNetwork exposure is present across interfaces that accept serialized data structures, and the required privilege level mandates that the attacker must be authorized to interact with the specific SharePoint component susceptible to the flawed deserialization routine.\nPost-exploitation impact includes full system compromise, unauthorized access to sensitive documents and databases hosted within the SharePoint environment, and potential pivoting to adjacent network resources."
}
CVE-2026-63514: Microsoft Office SharePoint Deserialization Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere