References https://nvd.nist.gov/vuln/detail/CVE-2022-38029 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-38029 https://cve.imfht.com/detail/CVE-2022-38029 https://www.sentinelone.com/vulnerability-database/cve-2022-38029/ https://github.com/SpiralBL0CK/SIDECHANNEL-CVE-2022-38029 https://cve.imfht.com/poc_detail/26346ff88e98af467e9344b20e590625e712e6eb https://www.rapid7.com/blog/post/2022/10/11/patch-tuesday-october-2022/ https://www.tenable.com/cve/CVE-2022-38029 https://cvepremium.circl.lu/vuln/CVE-2022-38029 https://www.secpod.com/blog/microsoft-october-patch-tuesday-addresses-84-security-vulnerabilities-including-two-zero-day/
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages DisclosurePoCCVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass(CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行