ZeroHour

CVE-2024-43464

mass

High-Privilege Deserialization RCE in Microsoft SharePoint Server

CVSS 3.1
7.2 high
EPSS
36%p98
Published
()
Modified
AI analysis

CVE-2024-43464 is a remote code execution vulnerability in on-premises Microsoft SharePoint Server caused by insecure deserialization of untrusted data (CWE-502), rated 7.2 High with a network attack vector. Exploitation requires high-privilege credentials (PR:H per the CVSS vector): an authenticated, highly privileged user submits crafted serialized data that SharePoint processes, causing arbitrary code to execute on the server with no user interaction required. A successful attacker gains code execution in the context of the SharePoint server, with high impact on the confidentiality, integrity and availability of the affected system and potentially the host running it. Organizations running self-hosted SharePoint Server are affected; Microsoft's cloud offering (SharePoint Online/Microsoft 365) is not listed among the affected products. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is documented for this specific CVE, but the Patch Tuesday release that fixed it addressed 79 vulnerabilities including four exploited zero-days, and EPSS estimates a roughly 36% probability of exploitation within 30 days (98th percentile).

What to do: Apply the SharePoint Server security update for CVE-2024-43464 from Microsoft's Patch Tuesday release and verify the update actually installed, given reports in the same release of a code defect that caused some earlier fixes to fail. Until patched, restrict and review high-privilege access to SharePoint (site/farm administrator accounts), since exploitation requires such credentials, and monitor SharePoint/IIS logs for unexpected authenticated activity. Prioritize internet-facing and centrally managed farms for emergency patching despite the lack of confirmed exploitation, in line with the elevated EPSS score.

Affected
microsoft sharepoint server
Estimated exposure
mass≈100,000+ on-premises SharePoint servers (tens of thousands of them internet-exposed), plausibly serving millions of users — Microsoft publishes no install counts, but public internet scans during recent SharePoint exploit waves have counted on the order of 35,000-100,000 internet-exposed SharePoint servers, and the total on-prem install base - largely…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

Vendors
microsoft
Products
sharepoint server
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news