CVE-2024-30043: Abusing URL Parsing Confusion to Exploit XXE on SharePoint Server and Cloud
ID: 31064e4e-c27e-5486-af98-e5ad2d96e049
STIX ID: report--31064e4e-c27e-5486-af98-e5ad2d96e049
Feed Name: Zero Day Initiative (ZDI) Blog
Threat Score
This analysis demonstrates an XXE vulnerability in SharePoint where malformed URLs (for example using a file://localhost\\c$/... form) can cause SPXmlDataSource/XmlSecureResolver to create an unrestricted policy, allowing local file access and remote exfiltration; the author documents experimentation with URL parsing and a practical bypass of SharePoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
