ZeroHour

CVE-2024-38018

large

Authenticated deserialization RCE in Microsoft SharePoint Server

CVSS 3.1
8.8 high
EPSS
51%p99
Published
()
Modified
AI analysis

CVE-2024-38018 is a remote code execution vulnerability in on-premises Microsoft SharePoint Server caused by insecure deserialization of untrusted data (CWE-502). Per its CVSS vector (network attack vector, low attack complexity, low privileges required, no user interaction), an attacker who has obtained low-privileged authenticated access to a network-reachable SharePoint server can trigger the flaw by submitting maliciously crafted serialized data. Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 8.8, High). Organizations running on-premises SharePoint Server are affected; the advisory is scoped to the on-premises product rather than SharePoint Online/Microsoft 365. No public proof-of-concept is known and it is not yet in CISA's KEV catalog, but its EPSS of ~51.5% (99th percentile) signals a high likelihood of exploitation within 30 days, and related reporting notes a Microsoft servicing code defect caused the earlier (July 2024) fix to be nixed, so some deployments may still be unpatched.

What to do: Install the latest SharePoint Server security update (September 2024 or later) on every on-premises SharePoint server, and because related reporting says a servicing defect caused the July 2024 fixes to be lost or removed, verify the patch actually applied and reapply it even if July updates were already installed. Restrict authenticated access to SharePoint (e.g., VPN or network segmentation), monitor these servers for suspicious activity, and treat exploitation risk as elevated given the ~51.5% EPSS score.

Affected
Microsoft SharePoint Server (on-premises)
Estimated exposure
largetens of thousands of internet-exposed SharePoint Server instances, with likely hundreds of thousands of total on-prem deployments — Public internet scans (e.g., Shodan/Censys) have consistently shown tens of thousands of SharePoint servers directly exposed to the internet, while SharePoint's ubiquity as an enterprise and government intranet platform implies total…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news