CVE-2021-27076
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
In plain language
AI Worth attentionCVE-2021-27076 is a remote “run arbitrary code” flaw in Microsoft SharePoint Server that does not require login, so a typical small business should treat it as a serious patch-needed risk if your SharePoint is reachable from the internet.
CVE-2021-27076 is a network-exposed Remote Code Execution issue in Microsoft SharePoint Server that is reachable without authentication or user interaction, enabling an attacker to run arbitrary code on the server (observed in real-world “StrikeShark” activity via SharkLoader).
What to do now
- Check whether Microsoft SharePoint Server is installed and exposed to the network (especially internet-facing access or any externally reachable endpoint).
- Identify your exact SharePoint product and service pack (e.g., SharePoint Foundation/Server versions and whether SP1/SP2 apply).
- Apply the Microsoft security updates for CVE-2021-27076 using Microsoft’s update guidance/advisory links (no fixed version numbers were provided in the findings).
- Verify the update was installed on the SharePoint servers and that the service is running the patched build.
- If you cannot patch immediately, restrict access so SharePoint is not reachable from the internet, and reduce exposure to only trusted networks/users until updates are applied.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-27076 and every CVE in our database. Create a free account — no credit card required.
Create Free Account