CVE-2023-29357

9.8CRITICAL

Microsoft SharePoint Server Elevation of Privilege Vulnerability

公開日: 6/14/2023更新日: 10/28/2025

CISA既知の悪用された脆弱性

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.

必要な対応:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

期限:

2024-01-31

既知のランサムウェア使用

説明

Microsoft SharePoint Server Elevation of Privilege Vulnerability

AI分析AIによる分析

影響を受ける製品

microsoftsharepoint_server
2019

参照