U.S. CISA adds Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38094 | Authenticated deserialization RCE in Microsoft SharePoint Server CVE-2024-38094 is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server, rated 7.2 (high) on CVSS 3.1 and classified by Microsoft as a remote code execution vulnerability. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the attack is network-reachable but requires an attacker who already holds high-privileged access, such as site collection or farm administrator credentials, to submit maliciously crafted serialized data to the server. Successful exploitation yields remote code execution on the SharePoint server with high impact to confidentiality, integrity, and availability, giving attackers a foothold for follow-on activity such as ransomware deployment. Any organization running on-premises SharePoint Server is potentially affected, while SharePoint Online in Microsoft 365 is a separate cloud service. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-22 with known ransomware use, and the EPSS of 50.9% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known. Do: Apply Microsoft's vendor-supplied mitigations and security updates for SharePoint Server as soon as possible; CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Limit internet exposure of SharePoint front-ends, review high-privileged site and farm administrator accounts for compromise or unusual activity, and prioritize patching given the confirmed ransomware use. No public PoC is known, but the 50.9% EPSS and KEV listing indicate attackers are actively working this flaw. | 7.2 | 51% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SharePoint Server deployments (roughly 10k-100k servers) |
Full article349 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Microsoft SharePoint Deserialization Vulnerability CVE-2024-38094 (CVSS v4 score: 7.2) to its Known Exploited Vulnerabilities (KEV) catalog.
An attacker with Site Owner permissions can exploit a vulnerability to inject and execute arbitrary code on SharePoint Server.
“An authenticated attacker with Site Owner permissions can use the vulnerability to inject arbitrary code and execute this code in the context of SharePoint Server.” reads the advisory published by Microsoft.
The vulnerability is due to an input validation error in the SharePoint Server Search component. An unauthenticated user could exploit this vulnerability by sending a specially crafted HTTP request to the vulnerable SharePoint server. This could allow the attacker to execute arbitrary code on the server, potentially taking over the system.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by November 12, 2024.
This week, U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added ScienceLogic SL1 flaw to its Known Exploited Vulnerabilities catalog.
ScienceLogic SL1 contains a vulnerability related to a third-party component. It has been fixed in versions 12.1.3+, 12.2.3+, and 12.3+, with patches available for older versions back to 10.1.x.
On September 24, 2024, cloud hosting provider Rackspace reported an issue with its ScienceLogic EM7 monitoring tool. A threat actor exploited a zero-day vulnerability in a non-Rackspace utility bundled with the ScienceLogic application. The security breach exposed low-sensitivity performance monitoring data, including customer usernames, account info, and encrypted internal credentials. Rackspace helped ScienceLogic address this issue. The patch is now available to all customers, and the company notified the impacted customers.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170157/security/u-s-cisa-adds-microsoft-sharepoint-flaw-known-exploited-vulnerabilities-catalog.html