CVE-2022-44690
Microsoft Sharepoint Server 2013 … 2019
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2022-44690 is a high-severity an unspecified weakness vulnerability in Microsoft Sharepoint Server. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 0.4% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SI-2 (Flaw Remediation) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
Microsoft SharePoint Server is affected by CVE-2022-44690, a remote code execution vulnerability disclosed on December 13, 2022. The flaw carries a CVSS 3.1 base score of 8.8 with an attack vector of network, low attack complexity, and low privileges required, allowing an authenticated attacker to execute arbitrary code with impacts to confidentiality, integrity, and availability.
An attacker with low-privileged access to a SharePoint deployment can exploit the vulnerability over the network without user interaction to achieve full remote code execution on the server. This enables the attacker to run malicious code, access sensitive data, modify content, or disrupt service operations within the affected SharePoint environment.
Microsoft has published guidance for the vulnerability in its security update guide at the referenced advisory URL, which includes details on available patches and mitigation steps for supported SharePoint Server versions. The associated EPSS score reached a peak of 0.3860 with a current value of 0.3022, indicating moderate and sustained exploitation interest following disclosure.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-47624
Vulnerability Data
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CWE(s)
Related Threats
Likely ATT&CK TechniquesAI
Techniques this vulnerability likely enables, inferred from its description, weakness type, and attributed-actor tradecraft. Confidence is per-technique.
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
Mitigating Controls (NIST 800-53 r5) AI
Directly requires timely application of vendor patches to eliminate the SharePoint RCE flaw before exploitation.
Enforces least privilege so that low-privileged authenticated accounts cannot reach the code paths used for remote code execution.
Access enforcement mechanisms can restrict the specific SharePoint operations and objects an authenticated user is allowed to invoke, limiting exploitability.