QID 110431

Date Published: 2023-04-12

QID 110431: Microsoft SharePoint Server and Foundation Update for April 2023

Microsoft has released April 2023 security updates to fix multiple security vulnerabilities.

This security update contains the following KBs:

KB5002375
KB5002373
KB5002383
KB5002385
KB5002381

QID Detection Logic (Authenticated):
Operating System: Windows
The detection extracts the Install Path for Microsoft Sharepoint via the Windows Registry. Below is the mapping of Filename, patched version and KB details checked for each applicable Product: ONETUTIL.DLL - 16.0.5391.1000 (KB5002385)
ONETUTIL.DLL - 16.0.10397.20002 (KB5002373)
PJINTL.DLL - 16.0.16130.20314 (KB5002375)
ONETUTIL.DLL - 15.0.5545.1000 (KB5002383)
MSOSERVER.DLL - 15.0.5545.1000 (KB5002381)

Successful exploitation allows spoofing.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Microsoft Security Guidance for more details pertaining to this vulnerability.

    KB5002375
    KB5002373
    KB5002383
    KB5002385
    KB5002381

    CVEs related to QID 110431

    Software Advisories
    Advisory ID Software Component Link
    April 2023 URL Logo portal.msrc.microsoft.com/en-us/security-guidance