Vulnerability record · CVE-2022-37961 · published 13 September 2022
CVE-2022-37961: Microsoft SharePoint Server remote code execution flaw
Microsoft · Sharepoint Enterprise Server
CVE-2022-37961 is a remote code execution vulnerability in Microsoft SharePoint Server, SharePoint Enterprise Server and SharePoint Foundation. It matters because a network-reachable SharePoint instance can be compromised by an authenticated low-privileged user, and the record gives no further detail on the underlying cause.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS make this a serious remote code execution risk, though it requires authentication and is not in KEV.
What it is
CVE-2022-37961 is a remote code execution vulnerability in Microsoft SharePoint Server, SharePoint Enterprise Server and SharePoint Foundation. It matters because a network-reachable SharePoint instance can be compromised by an authenticated low-privileged user, and the record gives no further detail on the underlying cause.
Impact
An attacker who can reach the server and authenticate with low privileges can execute arbitrary code in the context of the SharePoint service, gaining control of the affected host and its data.
Attack surface
Reached over the network via the SharePoint web interface or service endpoints (AV:N), requiring only low privileges (PR:L) and no user interaction (UI:N). No public exploit detail is provided in the record.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated likelihood of attempted exploitation. Reference tags are empty, so no exploit code or PoC is confirmed by the record.
What to do
- Apply the Microsoft security update for CVE-2022-37961 from the MSRC update guide as soon as possible.
- Restrict network access to SharePoint servers to trusted networks and required users only.
- Enforce least privilege and review accounts with site or service access to reduce the low-privilege attack path.
- Monitor for and remove unnecessary SharePoint service accounts or delegated permissions that widen the attack surface.
Detection
- Monitor SharePoint and IIS logs for unusual POST requests or web shell activity on SharePoint servers.
- Alert on unexpected child processes spawned by SharePoint worker processes (w3wp.exe).
- Track creation or modification of files in SharePoint web directories and layout folders.
- Correlate authentication events from low-privileged accounts with subsequent process or file activity on the server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-37961 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-37961), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.