CVE-2024-30043XML External Entity (XXE) Injection in Microsoft Sharepoint Enterprise Server 2016

Severity
7.5HIGHNVD
CNA6.5
EPSS
54.1%
top 1.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14
Latest updateAug 22

Description

Microsoft SharePoint Server Information Disclosure Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDmicrosoft/sharepoint_server< 16.0.17328.20292+2
CVEListV5microsoft/microsoft_sharepoint_server_201916.0.016.0.10409.20047
CVEListV5microsoft/microsoft_sharepoint_enterprise_server_201616.0.016.0.5448.1000
CVEListV5microsoft/microsoft_sharepoint_server_subscription_edition16.0.016.0.17328.20292

🔴Vulnerability Details

2
GHSA
GHSA-j424-2gw5-5mrv: Microsoft SharePoint Server Information Disclosure Vulnerability2024-05-14
CVEList
Microsoft SharePoint Server Information Disclosure Vulnerability2024-05-14

🔍Detection Rules

1
Suricata
ET HUNTING Microsoft Sharepoint SPXmlDataSource ASPX DataFile Fetch Inbound (CVE-2024-30043)2025-08-22

📋Vendor Advisories

1
Microsoft
Microsoft SharePoint Server Information Disclosure Vulnerability2024-05-14

🕵️Threat Intelligence

2
Trendmicro
CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud2024-05-30
Trendmicro
CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud2024-05-30
CVE-2024-30043 — XML External Entity (XXE) Injection | cvebase