CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability
Based on proof of active exploitation in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security hole affecting Microsoft Sharepoint Server to its list of known exploited vulnerabilities (KEV).
This significant remote code execution vulnerability, identified as CVE-2023-24955 (CVSS score: 7.2), enables arbitrary code execution by an authorized attacker with Site Owner capabilities.
An authorized attacker might remotely execute code on the SharePoint Server as a Site Owner through a network-based attack, according to a warning from Microsoft. Microsoft fixed the vulnerability in its May 2023 Patch Tuesday patches.
The update was made more than two months after CISA included CVE-2023-29357, a SharePoint Server privilege escalation vulnerabili...

