CVE-2023-24955
published 2023-05-09CVE-2023-24955: Microsoft SharePoint Server Remote Code Execution Vulnerability
PriorityP188high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-04-16
Exploited in the wild
EPSS
85.39%
99.7th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_sharepoint_enterprise_server_2016 | >= 16.0.0 < 16.0.5395.1000 | 16.0.5395.1000 |
| microsoft | microsoft_sharepoint_server_2019 | >= 16.0.0 < 16.0.10398.20000 | 16.0.10398.20000 |
| microsoft | microsoft_sharepoint_server_subscription_edition | >= 16.0.0 < 16.0.16130.20420 | 16.0.16130.20420 |
| microsoft | sharepoint_enterprise_server | — | — |
| microsoft | sharepoint_server | — | — |
| msrc | microsoft_sharepoint_enterprise_server_2016 | — | — |
| msrc | microsoft_sharepoint_server_2019 | — | — |
| msrc | microsoft_sharepoint_server_subscription_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect JWT tokens with signing algorithm set to 'none' in SharePoint OAuth authentication requests — this is the core auth bypass mechanism for CVE-2023-29357 (chained with CVE-2023-24955 for RCE). SharePoint skips signature validation when the JWT algorithm field is 'none' due to a logic flaw in ReadTokenCore(). ↗
- →Monitor SharePoint webroot for unexpected creation or modification of the file 'BDCMetadata.bdcm' under the BusinessDataMetadataCatalog directory, which is the payload staging location used in CVE-2023-24955 exploitation. ↗
- →A YARA rule is available to help network defenders analyze logs for signs of potential exploitation on their SharePoint servers using the CVE-2023-29357 PoC exploit (which is the auth bypass prerequisite for CVE-2023-24955 RCE). ↗
- →The exploit chain involves an unauthenticated attacker first spoofing a JWT authentication token to gain admin privileges (CVE-2023-29357), then using the SharePoint API to inject and execute code via CVE-2023-24955. Monitor SharePoint API calls made with newly elevated or anomalous admin tokens. ↗
- ·CVE-2023-24955 requires the attacker to already have authenticated Site Owner privileges on SharePoint Server. In practice, exploitation requires chaining with CVE-2023-29357 (auth bypass) to achieve unauthenticated RCE. Standalone exploitation of CVE-2023-24955 requires a privileged account. ↗
- ·The initially released public PoC (September 26, 2023) did not include full RCE capability for CVE-2023-24955 — it only demonstrated the CVE-2023-29357 auth bypass. However, subsequent PoCs including a Metasploit module implement the full chain. Defenders should not assume partial PoC availability limits attacker capability. ↗
- ·CISA confirmed active exploitation of CVE-2023-24955 but stated there is no evidence it has been used in ransomware attacks at the time of reporting. ↗
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vulncheck7.2HIGH
cisa7.2HIGH
vendor_msrc7.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft SharePoint Server Code Injection Vulnerability
cisa·2024-03-26·CVSS 7.2
CVE-2023-24955 [HIGH] CWE-94 Microsoft SharePoint Server Code Injection Vulnerability
Vulnerability: Microsoft SharePoint Server Code Injection Vulnerability
Affected: Microsoft SharePoint Server
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955; https://nvd.nist.gov/vuln/detail/CVE-2023-24955
Remediation Due Date: 2024-04-16
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability
vendor_msrc·2023-05-09·CVSS 7.2
CVE-2023-24955 [HIGH] CWE-94 Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
FAQ: How could an attacker exploit the vulnerability?
In a network-based attack, an authenticated attacker as a Site Owner could execute code remotely on the SharePoint Server.
Microsoft Office SharePoint: Microsoft Office SharePoint
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely;DOS:N/A
Reference: https://www.microsoft.com/download/details.aspx?familyid=7a299fb3-33f2-4417-809d-7bf31da6d14e
Reference: https://support.microsoft.com/help/5002397
Reference: https://www.microsoft.com/download/details.aspx?familyid=c9190144-e85b-4ded-9b6f-cc9b295054f3
Reference: https://support.microsoft.co
GHSA
GHSA-8vmr-gjcv-vm3c: Microsoft SharePoint Server Remote Code Execution Vulnerability
ghsa_unreviewed·2023-05-09
CVE-2023-24955 [HIGH] CWE-94 GHSA-8vmr-gjcv-vm3c: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
VulnCheck
Microsoft SharePoint Server Code Injection Vulnerability
vulncheck·2023·CVSS 7.2
CVE-2023-24955 [HIGH] CWE-94 Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Affected: Microsoft SharePoint
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.microsoft.com/en-us/security/blog/2025/04/09/stopping-attacks-against-on-premises-exchange-server-and-sharepoint-server-with-amsi/; https://www.rapid7.com/blog/post/dr-rapid7-q2-2025-incident-response-findings/; https://www.gstatic.com/security-marketing/m-trends-
Suricata
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM File Creation (CVE-2023-24955)
suricata·2024-11-06·CVSS 7.2
CVE-2023-24955 [HIGH] ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM File Creation (CVE-2023-24955)
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM File Creation (CVE-2023-24955)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM File Creation (CVE-2023-24955)"; flow:established,to_server; flowbits:set,ET.Sharepoint.CVE-2023-24955; http.method; content:"POST"; http.uri; content:"|2f|web|2f|GetFolderByServerRelativeUrl|28|"; content:"|2f|BusinessDataMetadataCatalog|2f 27 29 2f|Files|2f|add|28|url|3d|'"; fast_pattern; distance:0; content:"|2f|BusinessDataMetadataCatalog|2f|BDCMetadata|2e|bdcm"; distance:0; http.request_body; content:"Name|3d 22|WebServiceProxyNamespace|22|"; content:"|21 5b|CDATA|5b|"; distance:0; reference:cve,2023-24955; classtype:web-application-attack; sid:2057281; rev:1; metadata:affected_product Microsoft_Sharepoint, attack
Suricata
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)
suricata·2024-11-06·CVSS 7.2
CVE-2023-24955 [HIGH] ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)"; flow:established,to_server; flowbits:isset,ET.Sharepoint.CVE-2023-24955; http.method; content:"POST"; http.uri; content:"/_vti_bin/client.svc/ProcessQuery"; fast_pattern; endswith; http.request_body; content:"Name|3d 22|ReturnParameterCollection|22|"; content:"|3a|entityfile|3a|"; content:"|3a|lsifile|3a|"; reference:cve,2023-24955; classtype:web-application-attack; sid:2057282; rev:1; metadata:affected_product Microsoft_Sharepoint, attack_target Server, tls_state TLSDecrypt, created_at 2024_11_06, cve CVE_2023_24955, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence
Tenable
CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2026-07-16·CVSS 6.5
CVE-2026-32201 [MEDIUM] CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
## CVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
Four Microsoft SharePoint Server vulnerabilities are under active exploitation, prompting CISA to issue a hardening alert. An additional high-severity flaw recently patched adds pressure for organizations running on-premises deployments.
## Key Takeaways
CISA confirmed active exploitation of three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), used to gain unauthorized access, establish remote code execution, steal IIS machine keys and deploy malware for persistence.
Two additional SharePoint Server vulnerabilities disclosed on July 14, 2026, CVE-2026-55040 and CVE-2026-58644, were not yet
Bleepingcomputer
CISA tags Microsoft SharePoint RCE bug as actively exploited
blogs_bleepingcomputer·2024-03-27·CVSS 7.2
CVE-2023-29357 [HIGH] CISA tags Microsoft SharePoint RCE bug as actively exploited
## CISA tags Microsoft SharePoint RCE bug as actively exploited
## Sergiu Gatlan
These two SharePoint Server security vulnerabilities can be chained by unauthenticated attackers to gain RCE on unpatched servers, as STAR Labs researcher Nguyễn Tiến Giang (Janggggg) demonstrated during last year's March 2023 Pwn2Own contest in Vancouver.
A CVE-2023-29357 proof-of-concept exploit was released on GitHub on September 25, one day after the security researcher published a technical analysis describing the exploitation process.
Although the PoC exploit did not allow attackers to gain remote code execution on targeted systems, threat actors could still modify it to complete the chain with CVE-2023-24955 exploitation capabilities for RCE attacks.
Multiple PoC exploits targeting this chain have
Bleepingcomputer
CISA: Critical Microsoft SharePoint bug now actively exploited
blogs_bleepingcomputer·2024-01-12·CVSS 7.2
CVE-2023-24955 [HIGH] CISA: Critical Microsoft SharePoint bug now actively exploited
## CISA: Critical Microsoft SharePoint bug now actively exploited
## Sergiu Gatlan
"An attacker who successfully exploited this vulnerability could gain administrator privileges. The attacker needs no privileges nor does the user need to perform any action."
Remote attackers can also execute arbitrary code on compromised SharePoint servers via command injection when chaining this flaw with the CVE-2023-24955 SharePoint Server remote code execution vulnerability.
This Microsoft SharePoint Server exploit chain was successfully demoed by STAR Labs researcher Jang (Nguyễn Tiến Giang) during last year's March 2023 Pwn2Own contest in Vancouver, earning a $100,000 reward .
The researcher published a technical analysis on September 25 describing the exploitation process in detail.
Just one d
Tenable
Microsoft’s January 2024 Patch Tuesday Addresses 48 CVEs (CVE-2024-20674)
blogs_tenable·2024-01-09·CVSS 8.8
[HIGH] Microsoft’s January 2024 Patch Tuesday Addresses 48 CVEs (CVE-2024-20674)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Exploit released for Microsoft SharePoint Server auth bypass flaw
blogs_bleepingcomputer·2023-09-29·CVSS 7.2
CVE-2023-29357 [HIGH] Exploit released for Microsoft SharePoint Server auth bypass flaw
## Exploit released for Microsoft SharePoint Server auth bypass flaw
## Sergiu Gatlan
Proof-of-concept exploit code has surfaced on GitHub for a critical authentication bypass vulnerability in Microsoft SharePoint Server, allowing privilege escalation.
Tracked as CVE-2023-29357 , the security flaw can let unauthenticated attackers gain administrator privileges following successful exploitation in low-complexity attacks that don't require user interaction.
"An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user," Microsoft explained in June when it patched the vulnerability.
"An attacker who successfully exploited this vulnerab
Tenable
CVE-2023-29357, CVE-2023-24955: Exploit Chain Released for Microsoft SharePoint Server Vulnerabilities
blogs_tenable·2023-09-27·CVSS 7.2
[HIGH] CVE-2023-29357, CVE-2023-24955: Exploit Chain Released for Microsoft SharePoint Server Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three-plus years
blogs_talos·2023-05-09·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three-plus years
## Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three-plus years
Microsoft disclosed 40 vulnerabilities across its suite of products and software Tuesday, the fewest the company’s included in a Patch Tuesday since December 2019.
However, two of the vulnerabilities is being actively exploited in the wild, according to Microsoft, the fourth month in a row in which this is the case for the monthly roundup of security issues.
In all, this Patch Tuesday includes seven critical vulnerabilities and 33 that are considered “important.”
One of the zero-day vulnerabilities included this month is CVE-2023-29336 , an elevation of privilege vulnerability in the Win32k kernel mode driver. An adversary could exploit this vulnerability to gain SYSTEM privileges.
Qualys
Microsoft and Adobe Patch Tuesday, May 2023 Security Update Review
blogs_qualys·2023-05-09
Microsoft and Adobe Patch Tuesday, May 2023 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for May 2023
Adobe Patches for May 2023
Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in May Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Microsoft has addressed 49 vulnerabilities in its May Patch Tuesday edition. The security advisories cover various vulnerabilities in different produc
Talos
Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three-plus years
blogs_talos·2023-05-09·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday for May 2023 — Fewest vulnerabilities disclosed in a month in three-plus years
Microsoft disclosed 40 vulnerabilities across its suite of products and software Tuesday, the fewest the company’s included in a Patch Tuesday since December 2019.
However, two of the vulnerabilities is being actively exploited in the wild, according to Microsoft, the fourth month in a row in which this is the case for the monthly roundup of security issues.
In all, this Patch Tuesday includes seven critical vulnerabilities and 33 that are considered “important.”
One of the zero-day vulnerabilities included this month is CVE-2023-29336, an elevation of privilege vulnerability in the Win32k kernel mode driver. An adversary could exploit this vulnerability to gain SYSTEM privileges.
The most serious vulnerability disclosed Tuesday is CVE-2023-24941, a remote code execution vulnerability
Qualys
Microsoft Patch Tuesday, May 2023 Security Update Review | Qualys
blogs_qualys·2023-05-09
Microsoft Patch Tuesday, May 2023 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for May 2023
- Adobe Patches for May 2023
- Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in May Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Microsoft has addressed 49 vulnerabilities in its May Patch Tuesday edition. The security advisories cover various vulnerabilities in d
Crowdstrike
May 2023 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2023 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2023-05-09
Published
2024-03-26
Added to CISA KEV
Exploited in the wild