CVE-2024-43464
massHigh-Privilege Deserialization RCE in Microsoft SharePoint Server
CVE-2024-43464 is a remote code execution vulnerability in on-premises Microsoft SharePoint Server caused by insecure deserialization of untrusted data (CWE-502), rated 7.2 High with a network attack vector. Exploitation requires high-privilege credentials (PR:H per the CVSS vector): an authenticated, highly privileged user submits crafted serialized data that SharePoint processes, causing arbitrary code to execute on the server with no user interaction required. A successful attacker gains code execution in the context of the SharePoint server, with high impact on the confidentiality, integrity and availability of the affected system and potentially the host running it. Organizations running self-hosted SharePoint Server are affected; Microsoft's cloud offering (SharePoint Online/Microsoft 365) is not listed among the affected products. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is documented for this specific CVE, but the Patch Tuesday release that fixed it addressed 79 vulnerabilities including four exploited zero-days, and EPSS estimates a roughly 36% probability of exploitation within 30 days (98th percentile).
What to do: Apply the SharePoint Server security update for CVE-2024-43464 from Microsoft's Patch Tuesday release and verify the update actually installed, given reports in the same release of a code defect that caused some earlier fixes to fail. Until patched, restrict and review high-privilege access to SharePoint (site/farm administrator accounts), since exploitation requires such credentials, and monitor SharePoint/IIS logs for unexpected authenticated activity. Prioritize internet-facing and centrally managed farms for emergency patching despite the lack of confirmed exploitation, in line with the elevated EPSS score.
| microsoft sharepoint server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Microsoft SharePoint Server Remote Code Execution Vulnerability
- Vendors
- microsoft
- Products
- sharepoint server
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H