CISA warns that attackers are now exploiting a critical Microsoft SharePoint privilege escalation vulnerability that can be chained with another critical bug for remote code execution. Tracked as CVE-2023-29357, the security flaw enables remote attackers to get admin privileges on unpatched servers by circumventing authentication using spoofed JWT auth tokens. "An attacker who has gained access to spoofed JWT authentication tokens can use them to execute a network attack which bypasses authentication and allows them to gain access to the privileges of an authenticated user," Microsoft explains. "An attacker who successfully exploited this vulnerability could gain administrator privileges. The attacker needs no privileges nor does the user need to perform any action." Remote attackers can also execute arbitrary code on compromised SharePoint servers via command injection when chaining this flaw with the CVE-2023-24955 SharePoint Server remote code execution vulnerability. This Microsoft SharePoint Server exploit chain was successfully demoed by STAR Labs researcher Jang (Nguyễn Tiến Giang) during last year's March 2023 Pwn2Own contest in Vancouver, earning a $100,000 reward. The researcher published a technical analysis on September 25 describing the exploitation process in detail. Just one day later, a security researcher also released a CVE-2023-29357 proof-of-concept exploit on GitHub. Even though the exploit does not grant remote code execution on targeted systems, since ...
CISA: Critical Microsoft SharePoint bug now actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Jan 12, 2024
·Updated
Affected Software
1 affected component
Microsoft SharePoint Server=unknown
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical vulnerability in Microsoft SharePoint that is currently being exploited by attackers.
2
What security implications are discussed in the article?
The article highlights that the vulnerability allows for privilege escalation and can be chained with another exploit for remote code execution.
3
What is the identifier of the vulnerability mentioned in the article?
The vulnerability is tracked as CVE-2023-29357.
4
Which software is affected by the vulnerability?
The vulnerability affects Microsoft SharePoint Server.
5
What actions should organizations take in response to this vulnerability?
Organizations should apply necessary patches and monitor for signs of exploitation.