Microsoft SharePoint RCE bug exploited to breach corporate network
ID: 34ac69bd-0322-5405-b091-f94f41158c55
STIX ID: report--34ac69bd-0322-5405-b091-f94f41158c55
Feed Name: Bleeping Computer
Threat Score
Rapid7 investigated a network compromise where attackers exploited Microsoft SharePoint RCE CVE-2024-38094 (patched July 9, 2024) to plant a webshell, escalate to a domain admin via a compromised Exchange service account, and disable defenses by installing a malicious Huorong antivirus; they then performed credential harvesting (Mimikatz), lateral movement (Impacket), persistence via scheduled tasks, and attempted backup destruction though no data encryption was observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
