SharePoint Vulnerability Exploited in-the-Wild (Incident)
ID: 000f2d57-d1af-5be2-bf6c-a1a914b0e8c9
STIX ID: report--000f2d57-d1af-5be2-bf6c-a1a914b0e8c9
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-10-30
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers observed active in-the-wild exploitation of SharePoint CVE-2024-38094 that enabled attackers to install a webshell (ghostfile93.aspx), escalate privileges to a Microsoft Exchange service account, harvest credentials (Mimikatz), disable security controls (including via Horoung Antivirus), deploy remote access (FRP) and lateral-movement tooling (Impacket), and attempt destruction of backups — resulting in a multi-week undetected domain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
