Sceawere

Vulnerability Detail

CVE-2026-65665UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Office SharePoint Deserialization Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft SharePoint Server 2019
Attack Type
CWE-502: Deserialization of Untrusted Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-11T17:18:54.760Z",
  "pubdate": "2026-08-11T17:18:54.760Z",
  "executiveSummary": "A deserialization of untrusted data vulnerability exists in Microsoft Office SharePoint, exposing enterprise environments to severe security risks. This security flaw allows an authenticated attacker to execute arbitrary code remotely over the network. The vulnerability resides within the application logic handling serialized objects, where insufficient validation of untrusted input permits the instantiation of malicious payloads. Exploitation of this vulnerability requires network access and authorization, specifically leveraging authenticated privileges to interact with the vulnerable SharePoint endpoint. Successful execution grants the adversary the ability to compromise the underlying host system, leading to potential complete system compromise, data exfiltration, or lateral movement within the corporate network. The risk implications are critical, as SharePoint deployments often house sensitive organizational data and serve as core collaboration infrastructure. Organizations utilizing affected versions must prioritize defensive measures, including the application of official vendor patches, enforcing stringent network segmentation, and restricting administrative privileges to minimize the attack surface and prevent unauthorized code execution attempts.",
  "technicalDetails": "The vulnerability stems from the insecure handling and deserialization of untrusted data streams within Microsoft Office SharePoint. Specifically, the affected component fails to adequately sanitize or validate serialized objects before passing them to the underlying deserialization routines. When an authorized attacker submits a maliciously crafted payload containing serialized objects to the vulnerable network service, the application attempts to reconstruct the objects. During this reconstruction process, arbitrary code embedded within the payload is executed in the context of the SharePoint application service account. The root cause is rooted in unsafe deserialization practices, a common anti-pattern where complex data structures are decoded without proper type checking or cryptographic integrity validation. The attack flow begins with the adversary authenticating to the network and establishing a connection to the vulnerable Microsoft Office SharePoint endpoint. The attacker then crafts a specialized serialized payload designed to leverage gadget chains present within the runtime environment. Upon transmitting this payload over the network, the vulnerable SharePoint component processes the input and triggers the deserialization sequence. This action instantiates the malicious gadget chain, culminating in arbitrary code execution on the remote host without further user interaction. The network exposure is broad, as SharePoint instances are typically accessible across corporate networks or published externally. Authentication requirements dictate that the attacker must possess valid credentials to access the vulnerable functionality, while privilege requirements depend on the specific endpoint access levels, though successful exploitation generally escalates to the privileges of the executing service process. Post-exploitation impact includes full control over the SharePoint application tier, potential access to backend databases, and a strong foothold for persistent threats within the enterprise architecture."
}
CVE-2026-65665: Microsoft Office SharePoint Deserialization Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere