CVE-2023-24954: Microsoft SharePoint Server Information Disclosure Vulnerability
Published May 9, 2023
·Updated
Microsoft SharePoint Server Information Disclosure Vulnerability
Affected Software
20 affected componentsFixes available
Microsoft SharePoint Server 2019
Microsoft SharePoint Server Subscription Edition
Microsoft SharePoint Enterprise Server 2016
Microsoft Windows 10 1507<10.0.10240.19926
Microsoft Windows 10 1607<10.0.14393.5921
Microsoft Windows 10 1809<10.0.17763.4377
Microsoft Windows 10 20h2<10.0.19042.2965
Microsoft Windows 10 21h2<10.0.19044.2965
Microsoft Windows 10 22h2<10.0.19045.2965
Microsoft Windows 11 21h2<10.0.22000.1936
Microsoft Windows 11 22h2<10.0.22000.1702
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2022
Microsoft SharePoint Enterprise Server=2016
Microsoft SharePoint server
Microsoft SharePoint server=2019
Remediation
Event History
May 9, 2023
CVE Published
07:00 AM
Data Sourced
07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-24954?
CVE-2023-24954 is a vulnerability in Microsoft SharePoint Server that allows for information disclosure.
2
How severe is CVE-2023-24954?
CVE-2023-24954 is considered high severity with a CVSS score of 6.5.
3
Which versions of SharePoint Server are affected by CVE-2023-24954?
SharePoint Enterprise Server 2016, SharePoint Server Subscription Edition, and SharePoint Server 2019 are affected by CVE-2023-24954.
4
How can I fix CVE-2023-24954?
You can fix CVE-2023-24954 by applying the appropriate patches provided by Microsoft.
5
Where can I find more information about CVE-2023-24954?
You can find more information about CVE-2023-24954 on the Microsoft Security Response Center website.