logo

Exploit for under-siege SharePoint vuln reportedly in hands of ransomware crew

ID: 25e1f0aa-e90b-5e08-bd26-6abc69eed0f9

STIX ID: report--25e1f0aa-e90b-5e08-bd26-6abc69eed0f9

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Security researchers report that CVE-2023-29357 (critical EoP, 9.8) and the related CVE-2023-24955 can be chained to enable pre-auth remote code execution against Microsoft SharePoint; PoC code for one vulnerability is public and at least one researcher claims a ransomware group has a working exploit, prompting CISA to add CVE-2023-29357 to its Known Exploited Vulnerabilities catalog and urging organizations to apply SharePoint-specific patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.