Vulnerability record · CVE-2021-28474 · published 11 May 2021
CVE-2021-28474: Microsoft SharePoint Server remote code execution via interpretation conflict
Microsoft · Sharepoint Foundation
CVE-2021-28474 is a remote code execution vulnerability in Microsoft SharePoint Foundation and SharePoint Server, rooted in a CWE-436 interpretation conflict. An authenticated attacker with low privileges can send crafted requests over the network to execute code on the server, which matters because SharePoint is a widely deployed collaboration platform holding sensitive data.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (98.9th percentile) make this a serious, likely-targeted flaw despite no KEV listing.
What it is
CVE-2021-28474 is a remote code execution vulnerability in Microsoft SharePoint Foundation and SharePoint Server, rooted in a CWE-436 interpretation conflict. An authenticated attacker with low privileges can send crafted requests over the network to execute code on the server, which matters because SharePoint is a widely deployed collaboration platform holding sensitive data.
Impact
Successful exploitation gives the attacker code execution in the context of the SharePoint server, enabling data theft, lateral movement, or further compromise of the host. The CVSS vector rates confidentiality, integrity, and availability impact as high.
Attack surface
The flaw is reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so any authenticated SharePoint user can attempt it. No details on the specific endpoint or request shape are provided in the record.
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of exploitation activity. References are limited to the Microsoft patch advisory and a ZDI third-party advisory, with no public exploit tag.
What to do
- Apply the Microsoft security update for CVE-2021-28474 to all affected SharePoint Foundation and SharePoint Server instances.
- Restrict and audit authenticated access to SharePoint, removing unnecessary accounts and permissions.
- Place SharePoint behind network controls that limit exposure to trusted users and segments.
- Monitor vendor guidance and re-check for updated advisories, since the record lacks affected version detail.
Detection
- Review SharePoint server logs for anomalous or malformed requests from authenticated users that precede unexpected process execution.
- Alert on child processes spawned by SharePoint worker processes (for example w3wp.exe) that are not part of normal operations.
- Correlate authentication events with subsequent suspicious file writes or command execution on SharePoint hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28474 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-574/ | Third Party Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28474 | PatchVendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-574/ | Third Party Advisory |
Track CVE-2021-28474 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28474), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.