logo

Microsoft SharePoint RCE bug exploited to breach corporate network

ID: 34ac69bd-0322-5405-b091-f94f41158c55

STIX ID: report--34ac69bd-0322-5405-b091-f94f41158c55

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-11-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Rapid7 investigated a network compromise where attackers exploited Microsoft SharePoint RCE CVE-2024-38094 (patched July 9, 2024) to plant a webshell, escalate to a domain admin via a compromised Exchange service account, and disable defenses by installing a malicious Huorong antivirus; they then performed credential harvesting (Mimikatz), lateral movement (Impacket), persistence via scheduled tasks, and attempted backup destruction though no data encryption was observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.