ZDI-CAN-23930: ZDI-24-1204: Microsoft SharePoint SPThemes Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Sep 10, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-38018.
Affected Software
1 affected component
Microsoft SharePoint
Event History
Sep 10, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23930?
ZDI-CAN-23930 has a CVSS rating of 8.8, indicating a high severity vulnerability.
2
What software is affected by ZDI-CAN-23930?
ZDI-CAN-23930 affects installations of Microsoft SharePoint.
3
How do I fix ZDI-CAN-23930?
To fix ZDI-CAN-23930, apply the latest security updates provided by Microsoft for SharePoint.
4
Can ZDI-CAN-23930 be exploited without authentication?
No, ZDI-CAN-23930 requires authentication to exploit.
5
What type of attack does ZDI-CAN-23930 enable?
ZDI-CAN-23930 allows remote attackers to execute arbitrary code on affected installations.