CVE-2023-24955

7.2HIGH

Microsoft SharePoint Server Remote Code Execution Vulnerability

Published: 5/9/2023Updated: 10/28/2025

CISA Known Exploited Vulnerability

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date:

2024-04-16

Known Ransomware Use

Description

Microsoft SharePoint Server Remote Code Execution Vulnerability

AI AnalysisPowered by AI

Affected Products

microsoftsharepoint_enterprise_server
2016
microsoftsharepoint_server
-
microsoftsharepoint_server
2019

References