logo

CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud

ID: 31064e4e-c27e-5486-af98-e5ad2d96e049

STIX ID: report--31064e4e-c27e-5486-af98-e5ad2d96e049

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
70/100

Date Published: 2024-05-30

Date Updated: 2026-05-01

Author: Piotr Bazydło

...
...

This analysis demonstrates an XXE vulnerability in SharePoint where malformed URLs (for example using a file://localhost\\c$/... form) can cause SPXmlDataSource/XmlSecureResolver to create an unrestricted policy, allowing local file access and remote exfiltration; the author documents experimentation with URL parsing and a practical bypass of SharePoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.