CVE-2024-21318: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.5430.1000Patch KB5002541 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10406.20000Patch KB5002540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.0.10406.20000Patch KB5002539
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21318?
CVE-2024-21318 has been classified with a critical severity rating, indicating a significant risk of remote code execution.
How do I fix CVE-2024-21318?
To fix CVE-2024-21318, apply the relevant security patches provided by Microsoft for the affected SharePoint Server versions.
Which versions of SharePoint Server are affected by CVE-2024-21318?
CVE-2024-21318 affects Microsoft SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition.
What kind of attack does CVE-2024-21318 allow?
CVE-2024-21318 allows attackers to execute arbitrary code on the affected SharePoint server, potentially leading to data compromise.
Is there a workaround for CVE-2024-21318 until I can apply the patch?
There are no documented workarounds for CVE-2024-21318; applying the security update is the best course of action.