Junglewise Threat Intelligence

CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability

CVE-2023-24955 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-03-26

Technologies: Microsoft SharePoint Server 2019, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server. Vendors: Microsoft.

Executive brief

Microsoft SharePoint Server contains a code injection vulnerability (CWE-94) that allows an authenticated attacker with Site Owner privileges to execute code remotely on the server. The vulnerability stems from improper control of generation of code.

Affected products

  • Microsoft SharePoint Enterprise Server 2016 -
  • Microsoft SharePoint Server 2019 -
  • Microsoft SharePoint Server Subscription Edition -

Timeline

  • 2023-05-09: disclosed: NVD Published Date
  • 2024-03-26: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-04-16: other: CISA Due Date for remediation

Related threats