Skip to content
Auto-CTI
Back to today
CRITICAL A3

Microsoft SharePoint - Zero-Day and Critical Vulnerabilities Patched

A BSI RSS-Newsfeed BSI-IT-Sicherheitsmitteilungen (BITS ·

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key insight

The BSI has documented critical and zero-day vulnerabilities in Microsoft SharePoint without providing specific CVE identifiers or details on active exploitation , indicating a general security advisory without active-campaign context.

Description

The BSI has identified and patched critical and zero-day vulnerabilities in Microsoft SharePoint. Without available CVE details or exploitation status, it is unclear whether patch management is immediately required or if this is a preventive advisory. The notification originates from a government agency (BSI) and should be treated as part of routine patch-management procedures. Organizations should await official Microsoft security bulletins to identify specific vulnerabilities, affected versions, and patch priorities.

Risk score

37
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.21
freshness factor
0.50
exploitability factor
1.00
days old
58.00
vendor mismatch penalty
0.00
consensus penalty
-3.00

Path: operational

Consensus check

The pipeline self-checks before delivery. These rules lowered the score:

  • TTP_SKIPPED TTP mapping skipped (placeholder or aggregation article) −3
Consensus penalty:
−3.0
Total penalty:
−3.0
ESC