CVE-2023-29357

9.8CRITICAL

Microsoft SharePoint Server Elevation of Privilege Vulnerability

发布于: 6/14/2023更新于: 10/28/2025

CISA已知被利用漏洞

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.

所需操作:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

截止日期:

2024-01-31

已知勒索软件使用

描述

Microsoft SharePoint Server Elevation of Privilege Vulnerability

AI分析AI驱动

受影响产品

microsoftsharepoint_server
2019

参考资料