CVE-2018-0909: Microsoft Project Server

High severity, CVSS 8.8. EPSS: 4.5% chance of exploitation in the next 30 days.

Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0910, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923, CVE-2018-0944 and CVE-2018-0947.

Affected products

  • Microsoft Project Server: version 2013 only
  • Microsoft SharePoint Enterprise Server: version 2016 only

Published 2018-03-14. Last modified 2026-06-17.