ZDI-24-1204: Microsoft SharePoint SPThemes Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Sep 10, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-38018.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Sep 10, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-1204?
The severity of ZDI-24-1204 is rated at 8.8, indicating a high risk level.
2
How do I fix ZDI-24-1204?
To fix ZDI-24-1204, apply the latest security updates provided by Microsoft for SharePoint.
3
What is the vulnerability type of ZDI-24-1204?
ZDI-24-1204 is a remote code execution vulnerability.
4
Do I need authentication to exploit ZDI-24-1204?
Yes, authentication is required to exploit the ZDI-24-1204 vulnerability.
5
Which software is affected by ZDI-24-1204?
ZDI-24-1204 affects Microsoft SharePoint installations.