⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.. Due date: 2024-04-16.

CVE-2023-24955Code Injection in Microsoft Sharepoint Enterprise Server 2016

CWE-94Code Injection12 documents10 sources
Severity
7.2HIGHNVD
EPSS
91.6%
top 0.32%
CISA KEV
KEVRansomware
Added 2024-03-26
Due 2024-04-16
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedMay 9
KEV addedMar 26
KEV dueApr 16
Latest updateNov 6
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8vmr-gjcv-vm3c: Microsoft SharePoint Server Remote Code Execution Vulnerability2023-05-09
CVEList
Microsoft SharePoint Server Remote Code Execution Vulnerability2023-05-09
VulnCheck
Microsoft SharePoint Server Code Injection Vulnerability2023

💥Exploits & PoCs

1
Metasploit
Sharepoint Dynamic Proxy Generator Unauth RCE

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM File Creation (CVE-2023-24955)2024-11-06
Suricata
ET WEB_SPECIFIC_APPS Microsoft Sharepoint BDCM Execution (CVE-2023-24955)2024-11-06

📋Vendor Advisories

2
CISA
Microsoft SharePoint Server Code Injection Vulnerability2024-03-26
Microsoft
Microsoft SharePoint Server Remote Code Execution Vulnerability2023-05-09

🕵️Threat Intelligence

1
Bleepingcomputer
CISA: Critical Microsoft SharePoint bug now actively exploited2024-01-12
CVE-2023-24955 — Code Injection in Microsoft | cvebase