Junglewise Threat Intelligence

CVE-2024-38094: Microsoft SharePoint Deserialization Vulnerability

CVE-2024-38094 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2024-10-22

Technologies: Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, Microsoft SharePoint Server 2016 Enterprise Edition, Microsoft SharePoint. Vendors: Microsoft.

Executive brief

Microsoft SharePoint contains a deserialization vulnerability (CWE-502) that allows for remote code execution. An authenticated attacker with high privileges can exploit this flaw over the network to achieve full system compromise.

Affected products

  • Microsoft SharePoint Server Subscription Edition
  • Microsoft SharePoint Server 2016 Enterprise Edition
  • Microsoft SharePoint Server 2019

Timeline

  • 2024-07-09: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2024-07-09: patched: Vendor advisory and patch released.
  • 2024-10-22: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
  • 2024-10-22: exploited: Confirmed as exploited in the wild.

Related threats