CVE-2023-24955
7.2HIGHMicrosoft SharePoint Server Remote Code Execution Vulnerability
Veröffentlicht: 5/9/2023Aktualisiert: 10/28/2025
CISA Bekannte Ausgenutzte Schwachstelle
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Erforderliche Maßnahme:
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Fälligkeitsdatum:
2024-04-16
Bekannte Ransomware-Nutzung
Beschreibung
Microsoft SharePoint Server Remote Code Execution Vulnerability
KI-AnalyseKI-gestützt
Betroffene Produkte
microsoftsharepoint_enterprise_server
2016
microsoftsharepoint_server
-
microsoftsharepoint_server
2019
Referenzen
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955PatchVendor Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955PatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-24955US Government Resource