First published: Tue May 09 2023(Updated: )
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft SharePoint Enterprise Server 2016 | ||
Microsoft SharePoint Server 2019 | ||
Microsoft SharePoint Server Subscription Edition | ||
Microsoft SharePoint Enterprise Server | =2016 | |
Microsoft SharePoint Server | ||
Microsoft SharePoint Server | =2019 | |
Microsoft SharePoint Server |
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24955 is a vulnerability in Microsoft SharePoint Server that allows remote code execution.
CVE-2023-24955 has a severity rating of 7.2 (critical).
CVE-2023-24955 affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016.
You can fix CVE-2023-24955 by applying the relevant patches provided by Microsoft.
You can find the patches for CVE-2023-24955 on the Microsoft website.