CVE-2026-33112: SharePoint XmlValidator Bypass Enables Low-Privilege RCE
blog.viettelcybersecurity.com | 漏洞 | CVE-2026-33112 | #rce | #deserialization | #sharepoint | #xml | #cve-2026-33112 | #performancepoint
摘要
CVE-2026-33112:通过 XSD schema 网络导入绕过 SharePoint XmlValidator 校验,再经 PerformancePoint PPSAuthoringService 触发 ExcelDataSet 反序列化,实现低权限 RCE。
- 发布时间
- 收录时间
Skip to content