References https://msrc.microsoft.com/update-guide/en-US/security-guidance/advisory/CVE-2022-38008 https://nvd.nist.gov/vuln/detail/CVE-2022-38008 https://www.rapid7.com/db/vulnerabilities/microsoft-sharepoint-cve-2022-38008/ https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-sharepoint-enterprise-server-2016-language-pack-september-13-2022-kb5002142-ebc3e431-10d4-4ff3-b2d3-2754329ca3a6 https://github.com/advisories/GHSA-xgh6-7v4c-vr2f https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-sharepoint-foundation-2013-september-13-2022-kb5002159-e53543c7-e1de-4884-9fcc-ebf99c181b11 https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-sharepoint-server-subscription-edition-september-13-2022-kb5002271-9b21704b-ce7b-4da8-93e4-b0d6f9dbbd8d https://avd.aliyun.com/detail?id=AVD-2022-38008 https://zhuanlan.zhihu.com/p/564562988 https://support.microsoft.com/zh-cn/topic/sharepoint-foundation-2013-%E5%AE%89%E5%85%A8%E6%9B%B4%E6%96%B0%E8%AF%B4%E6%98%8E-2022-%E5%B9%B4-9-%E6%9C%88-13-%E6%97%A5-kb5002159-e53543c7-e1de-4884-9fcc-ebf99c181b11
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page DisclosurePoCsharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata DisclosurePoCsharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages DisclosurePoCCVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass(CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行