Microsoft originally listed a SharePoint Server vulnerability as a spoofing issue with a CVSS score of 6.5, but newly published technical details show it actually enables authenticated remote code execution. The finding comes from Viettel Cyber Security researcher Dinh Ho Anh Khoa, who released full technical details today.

The flaw requires authentication, so it is not exposed to unauthenticated internet attackers. However, in environments where users have low-level access, an attacker could exploit it to execute code on the server. That is a significantly more serious outcome than spoofing, and the initial severity rating may have led some organisations to deprioritise the fix.

The case highlights how vendor misclassification can distort risk assessments and patch management decisions. It also underscores the value of independent security research in verifying and correcting vendor severity claims.