• News/
  • https://www.bleepingcomputer.com/news/security/cisa-tags-microsoft-sharepoint-rce-bug-as-actively-exploited/

CISA tags Microsoft SharePoint RCE bug as actively exploited

BleepingComputer
·
Sergiu Gatlan
·
Published Mar 27, 2024
·
Updated

CISA warns that attackers are now exploiting a Microsoft SharePoint code injection vulnerability that can be chained with a critical privilege escalation flaw for pre-auth remote code execution attacks. Tracked as CVE-2023-24955, this SharePoint Server vulnerability enables authenticated attackers with Site Owner privileges to execute code remotely on vulnerable servers. The second flaw (CVE-2023-29357) allows remote attackers to gain admin privileges on vulnerable SharePoint servers by circumventing authentication using spoofed JWT auth tokens. These two SharePoint Server security vulnerabilities can be chained by unauthenticated attackers to gain RCE on unpatched servers, as STAR Labs researcher Nguyễn Tiến Giang (Janggggg) demonstrated during last year's March 2023 Pwn2Own contest in Vancouver. A CVE-2023-29357 proof-of-concept exploit was released on GitHub on September 25, one day after the security researcher published a technical analysis describing the exploitation process. Although the PoC exploit did not allow attackers to gain remote code execution on targeted systems, threat actors could still modify it to complete the chain with CVE-2023-24955 exploitation capabilities for RCE attacks. Multiple PoC exploits targeting this chain have since surfaced online (including one released by Star Labs), making it easier for less skilled attackers to use it in their attacks. One month later, CISA added the CVE-2023-29357 flaw to its Known Exploited Vulnerabilities Catalog a...

Read full article

Affected Software

1 affected component
Microsoft SharePoint Server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution (RCE) vulnerability in Microsoft SharePoint that is currently being exploited by attackers.

2

What security implications are discussed in the article?

The article highlights the risks associated with a code injection vulnerability in SharePoint that can lead to pre-auth remote code execution and privilege escalation.

3

What specific vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2023-24955.

4

Who has warned about the exploitation of this vulnerability?

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the exploitation of this vulnerability.

5

What software is affected by the vulnerability?

The affected software is Microsoft SharePoint Server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203