CVE-2023-24955
KEV ransomwarelargeAuthenticated Code Injection RCE in Microsoft SharePoint Server (Actively Exploited)
CISA: Microsoft SharePoint Server Code Injection Vulnerability
CVE-2023-24955 is a code injection vulnerability (CWE-94) in on-premises Microsoft SharePoint Server that enables remote code execution over the network (CVSS 3.1: 7.2, AV:N/AC:L/PR:H/UI:N). Exploitation requires authentication with high privileges — e.g., a SharePoint site administrator account — and no user interaction, so an attacker who has obtained elevated site credentials can send crafted requests that execute code on the SharePoint server. A successful attacker gains code execution in the context of the SharePoint service, with high impact on confidentiality, integrity, and availability, providing a foothold for lateral movement or ransomware deployment. Organizations running affected on-premises SharePoint Server releases are affected; the flaw was demonstrated at Pwn2Own and Microsoft patched it in the May 2023 Patch Tuesday updates. The bug is now exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-03-26 with known ransomware use, and EPSS places its 30-day exploitation probability at 85.4% (100th percentile).
What to do: Apply Microsoft's May 2023 (or later) security updates for SharePoint Server immediately, prioritizing internet-facing servers; CISA's KEV entry requires federal agencies to apply vendor mitigations or discontinue use of the product. Audit and tighten accounts holding SharePoint site-administrator rights, and hunt for signs of exploitation such as unexpected site-admin activity or unusual process launches from SharePoint service accounts. Public reporting on the 2024 exploitation suggests it may be chained with SharePoint privilege-escalation flaw CVE-2023-29357 to achieve unauthenticated access, so ensure both flaws are patched.
| Microsoft SharePoint Server (on-premises) | — |
| Microsoft SharePoint Enterprise Server (CPE listing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft SharePoint Server Remote Code Execution Vulnerability
- Affected
- Microsoft SharePoint Server
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- sharepoint enterprise server, sharepoint server
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H