Executive brief
Microsoft SharePoint contains a deserialization vulnerability (CWE-502) that allows for remote code execution. An authenticated attacker with high privileges can exploit this flaw over the network to achieve full system compromise.
Affected products
- Microsoft SharePoint Server Subscription Edition
- Microsoft SharePoint Server 2016 Enterprise Edition
- Microsoft SharePoint Server 2019
Timeline
- 2024-07-09: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2024-07-09: patched: Vendor advisory and patch released.
- 2024-10-22: kev added: Added to CISA's Known Exploited Vulnerabilities (KEV) catalog.
- 2024-10-22: exploited: Confirmed as exploited in the wild.