EXPOSURES › CVE-2023-24955
CVE-2023-24955
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn authenticated attacker with Site Owner privileges could remotely execute code via a code injection vulnerability in Microsoft SharePoint Server.
This unpatched vulnerability allowed remote code execution for authenticated attackers holding Site Owner privileges, directly enabling ransomware deployment and data exfiltration. DIB organizations must ensure SharePoint is patched and least-privilege access is enforced to prevent similar compromises. The failure stems from neglecting to apply known security updates, leading to an actively exploited, ransomware-linked breach.
Shame score — A known, unpatched code injection flaw was actively exploited in the wild to deploy ransomware, demonstrating severe negligence and avoidable risk.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |