漏洞描述 从 Word 等调用应用程序使用 URL 协议调用 MSDT 时存在远程执行代码漏洞。成功利用此漏洞的攻击者可以使用调用应用程序的权限运行任意代码。攻击者可以安装程序、查看、更改或删除数据,或者在用户权限允许的上下文中创建新帐户。
相关漏洞推荐 POC sharepoint-lists-api-disclosure: Microsoft SharePoint - List API Disclosure POC sharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure POC sharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure POC sharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata Disclosure POC sharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行 Microsoft Web Deploy 需授权 反序列化漏洞 可导致任意代码执行 POC CVE-2019-0604: Microsoft SharePoint - Remote Code Execution POC CVE-2020-0646: Microsoft .NET Framework - Remote Code Execution POC CVE-2000-0114: Microsoft FrontPage Extensions - Information Disclosure POC CVE-2008-1547: Microsoft OWA Exchange Server 2003 - 'redir.asp' Open Redirection POC CVE-2015-1635: Microsoft Windows 'HTTP.sys' - Remote Code Execution