ZeroHour

CVE-2023-24955

KEV ransomwarelarge

Authenticated Code Injection RCE in Microsoft SharePoint Server (Actively Exploited)

CISA: Microsoft SharePoint Server Code Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
85%p100
Published
()
KEV added
AI analysis

CVE-2023-24955 is a code injection vulnerability (CWE-94) in on-premises Microsoft SharePoint Server that enables remote code execution over the network (CVSS 3.1: 7.2, AV:N/AC:L/PR:H/UI:N). Exploitation requires authentication with high privileges — e.g., a SharePoint site administrator account — and no user interaction, so an attacker who has obtained elevated site credentials can send crafted requests that execute code on the SharePoint server. A successful attacker gains code execution in the context of the SharePoint service, with high impact on confidentiality, integrity, and availability, providing a foothold for lateral movement or ransomware deployment. Organizations running affected on-premises SharePoint Server releases are affected; the flaw was demonstrated at Pwn2Own and Microsoft patched it in the May 2023 Patch Tuesday updates. The bug is now exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-26 with known ransomware use, and EPSS places its 30-day exploitation probability at 85.4% (100th percentile).

What to do: Apply Microsoft's May 2023 (or later) security updates for SharePoint Server immediately, prioritizing internet-facing servers; CISA's KEV entry requires federal agencies to apply vendor mitigations or discontinue use of the product. Audit and tighten accounts holding SharePoint site-administrator rights, and hunt for signs of exploitation such as unexpected site-admin activity or unusual process launches from SharePoint service accounts. Public reporting on the 2024 exploitation suggests it may be chained with SharePoint privilege-escalation flaw CVE-2023-29357 to achieve unauthenticated access, so ensure both flaws are patched.

Affected
Microsoft SharePoint Server (on-premises)
Microsoft SharePoint Enterprise Server (CPE listing)
Estimated exposure
large≈ tens of thousands of on-premises SharePoint servers (10k–100k exposed systems) — Based on public internet-wide scans showing tens of thousands of exposed SharePoint hosts, plus SharePoint Server's broad enterprise and government on-prem footprint; the exact install base is unknown and internally hosted deployments are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft SharePoint Server
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
sharepoint enterprise server, sharepoint server
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news