Junglewise Threat Intelligence

CVE-2023-29357: Microsoft SharePoint Server Privilege Escalation Vulnerability

CVE-2023-29357 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-10

Technologies: Microsoft SharePoint Server, Microsoft SharePoint Server 2019. Vendors: Microsoft.

Executive brief

Microsoft SharePoint Server contains a vulnerability in the authentication process that allows an unauthenticated attacker to bypass security measures using spoofed JWT tokens. By exploiting this flaw, an attacker can gain administrative privileges and execute network-based attacks without user interaction.

Affected products

  • Microsoft SharePoint Server 2019

Timeline

  • 2023-06-13: disclosed: NVD Published Date
  • 2024-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-31: other: CISA KEV remediation due date

Related threats