Executive brief
Microsoft SharePoint Server contains a vulnerability in the authentication process that allows an unauthenticated attacker to bypass security measures using spoofed JWT tokens. By exploiting this flaw, an attacker can gain administrative privileges and execute network-based attacks without user interaction.
Affected products
- Microsoft SharePoint Server 2019
Timeline
- 2023-06-13: disclosed: NVD Published Date
- 2024-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-31: other: CISA KEV remediation due date