logo

CISA: Critical Microsoft SharePoint bug now actively exploited

ID: 96c40db2-2e8a-5701-9ce8-2ffb87969a43

STIX ID: report--96c40db2-2e8a-5701-9ce8-2ffb87969a43

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA and multiple researchers highlight a critical SharePoint privilege‑escalation flaw (CVE-2023-29357) that can be combined with CVE-2023-24955 to achieve remote code execution; public proof‑of‑concepts and demos (including a Pwn2Own chain) have emerged, and CISA placed CVE-2023-29357 on its Known Exploited Vulnerabilities Catalog, requiring U.S. federal agencies to patch by January 31 — lowering the exploitation bar for unpatched SharePoint servers and raising risk for organizations that do not update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.