logo

SharePoint Vulnerability Exploited in-the-Wild (Incident)

ID: 000f2d57-d1af-5be2-bf6c-a1a914b0e8c9

STIX ID: report--000f2d57-d1af-5be2-bf6c-a1a914b0e8c9

Feed Name: Wiz Cloud Threat Landscape

Threat Score
84/100

Date Published: 2024-10-30

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers observed active in-the-wild exploitation of SharePoint CVE-2024-38094 that enabled attackers to install a webshell (ghostfile93.aspx), escalate privileges to a Microsoft Exchange service account, harvest credentials (Mimikatz), disable security controls (including via Horoung Antivirus), deploy remote access (FRP) and lateral-movement tooling (Impacket), and attempt destruction of backups — resulting in a multi-week undetected domain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.