CISA tags Microsoft SharePoint RCE bug as actively exploited
ID: 4673c2a7-f991-5515-b7a9-419e15d7d08b
STIX ID: report--4673c2a7-f991-5515-b7a9-419e15d7d08b
Feed Name: Bleeping Computer
Threat Score
CISA warns that two SharePoint Server flaws (CVE-2023-24955 code injection and CVE-2023-29357 JWT auth bypass) can be chained to achieve pre-auth remote code execution; public PoCs and demonstrations exist, and both CVEs were added to CISA's Known Exploited Vulnerabilities catalog with mandated federal patching timelines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
