Headline
CVE-2023-33134: Microsoft SharePoint Server Remote Code Execution Vulnerability
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Within a SharePoint site, the attacker must be authenticated, and they would need to have the “Use Remote Interfaces” and “Add and Customize Pages” permissions on a Policy Center site to be able to exploit this vulnerability.