CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability

Based on proof of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security hole affecting Microsoft Sharepoint Server to its list of known exploited vulnerabilities (KEV).

This significant remote code execution vulnerability, identified as CVE-2023-24955 (CVSS score: 7.2), enables arbitrary code execution by an authorized attacker with Site Owner capabilities.

An authorized attacker might remotely execute code on the SharePoint Server as a Site Owner through a network-based attack, according to a warning from Microsoft. Microsoft fixed the vulnerability in its May 2023 Patch Tuesday patches.

The update was made more than two months after CISA included CVE-2023-29357, a SharePoint Server privilege escalation vulnerability, in its KEV catalog read more CISA Warns Hackers Actively Attacking Microsoft SharePoint Vulnerability.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *