New Microsoft SharePoint Vulnerability: CISA Issues Warning
ID: 8282f556-078c-5768-ac36-196ab31676fa
STIX ID: report--8282f556-078c-5768-ac36-196ab31676fa
Feed Name: Cyble Blog
Threat Score
CISA has issued an advisory for CVE-2024-38094, a high-severity deserialization vulnerability in Microsoft SharePoint (CVSSv3.1 7.2) that allows authenticated Site Owner accounts to inject and execute arbitrary code; proof-of-concept code is publicly available and the issue is listed in CISA's KEV catalog, so organizations should apply Microsoft patches and adopt mitigations such as patch management, network segmentation, monitoring, and incident response planning immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
