CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Other sources
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.16130.20420Patch KB5002390 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10398.20000Patch KB5002389 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5395.1000Patch KB5002397 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2023-24955?
CVE-2023-24955 is a vulnerability in Microsoft SharePoint Server that allows remote code execution.
How severe is CVE-2023-24955?
CVE-2023-24955 has a severity rating of 7.2 (critical).
Which versions of SharePoint Server are affected by CVE-2023-24955?
CVE-2023-24955 affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
How can I fix CVE-2023-24955?
You can fix CVE-2023-24955 by applying the relevant patches provided by Microsoft.
Where can I find the patches for CVE-2023-24955?
You can find the patches for CVE-2023-24955 on the Microsoft website.