cbcvebase.
CVE-2023-29357
published 2023-06-14

CVE-2023-29357: Microsoft SharePoint Server Elevation of Privilege Vulnerability

PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2024-01-31
Exploited in the wild
EPSS
99.65%
99.9th percentile
Microsoft SharePoint Server Elevation of Privilege Vulnerability

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10399.2000516.0.10399.20005
microsoftsharepoint_server
msrcmicrosoft_sharepoint_server_2019

Detection & IOCsextracted from sources · hover to see the quote

otherspoofed JWT authentication token
yara
YARA rule available to analyze logs for signs of CVE-2023-29357 PoC exploitation
  • Monitor SharePoint Server logs for spoofed JWT authentication tokens being submitted by unauthenticated remote clients — this is the core mechanism of CVE-2023-29357 exploitation.
  • Hunt for exploit chain activity combining CVE-2023-29357 (auth bypass via spoofed JWT) with CVE-2023-24955 (code injection/RCE by authenticated Site Owner) — unauthenticated RCE is achievable when both are chained.
  • The public PoC exploit outputs details of admin users with elevated privileges and supports both single-target and mass-exploit modes — look for bulk authentication probe patterns against SharePoint endpoints.
  • A YARA rule exists specifically for detecting CVE-2023-29357 PoC exploitation artifacts in SharePoint server logs — deploy it for log-based threat hunting.
  • No user interaction or attacker privileges are required to exploit CVE-2023-29357 — any unauthenticated inbound request to SharePoint that results in elevated session tokens should be treated as suspicious.
  • ·The public GitHub PoC for CVE-2023-29357 does not include RCE capability by itself — full unauthenticated RCE requires chaining with CVE-2023-24955. Defenders should treat both CVEs as a combined attack surface.
  • ·CVE-2023-29357 was patched in Microsoft's June 2023 Patch Tuesday and CVE-2023-24955 in May 2023 Patch Tuesday — systems not yet patched to those cumulative updates remain fully vulnerable to the unauthenticated RCE chain.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.