Microsoft SharePoint RCE flaw exploits in the wild – you've had 3 months to patch
ID: d6f29a98-61a1-572e-b3be-619f136acdca
STIX ID: report--d6f29a98-61a1-572e-b3be-619f136acdca
Feed Name: The Register (Security)
Threat Score
CISA has reported active exploitation of a Microsoft SharePoint deserialization vulnerability (CVE-2024-38094) that allows authenticated attackers with Site Owner permissions to inject and execute arbitrary code. Microsoft patched the issue (CVSS 7.2) and a public proof-of-concept exists; CISA added the flaw to its Known Exploited Vulnerabilities catalog, requiring federal agencies to apply the fix and urging all organizations to prioritize remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
