cbcvebase.
CVE-2023-33160
published 2023-07-11

CVE-2023-33160: Microsoft SharePoint Server Remote Code Execution Vulnerability

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.32%
90.1th percentile
Microsoft SharePoint Server Remote Code Execution Vulnerability

Affected

8 ranges
VendorProductVersion rangeFixed in
microsoftmicrosoft_sharepoint_enterprise_server_2016>= 16.0.0 < 16.0.5404.100016.0.5404.1000
microsoftmicrosoft_sharepoint_server_2019>= 16.0.0 < 16.0.10400.2000816.0.10400.20008
microsoftmicrosoft_sharepoint_server_subscription_edition>= 16.0.0 < 16.0.16130.2064216.0.16130.20642
microsoftsharepoint_server
microsoftsharepoint_server
msrcmicrosoft_sharepoint_enterprise_server_2016
msrcmicrosoft_sharepoint_server_2019
msrcmicrosoft_sharepoint_server_subscription_edition

Detection & IOCsextracted from sources · hover to see the quote

  • Attacker must be authenticated as at least a Site Member (PR:L) — monitor for authenticated low-privileged users invoking SharePoint APIs with anomalous or specially-formatted serialized input payloads
  • Exploitation vector is deserialization of unsafe data via vulnerable SharePoint APIs — inspect SharePoint ULS/IIS logs for malformed or unexpected serialized data submitted to SharePoint API endpoints
  • Exploitation requires a user to access a susceptible API on an affected SharePoint version with specially-formatted input — alert on unusual POST requests to SharePoint API paths containing binary/serialized content types from low-privileged accounts
  • ·Exploit has not been publicly disclosed or observed in the wild at time of advisory publication — prioritize patching over detection tuning but maintain monitoring posture
  • ·Successful exploitation leads to full CIA impact (RCE with potential downtime) — treat any confirmed exploitation as a critical incident

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.