Patched SharePoint vulnerability now being exploited in the wild, here's why
…SharePoint’s local Security Token Service (STS) certificate thumbprint lookup to force the application to accept a forged token. The attacker then gets full site user or admin access without valid credentials…