CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability
ID: 11aeddb6-2709-57b0-99d9-9a74d298629a
STIX ID: report--11aeddb6-2709-57b0-99d9-9a74d298629a
Feed Name: The Hacker News
CISA added CVE-2023-24955, a CVSS 7.2 remote code execution vulnerability in Microsoft SharePoint Server that allows an authenticated Site Owner to run arbitrary code, to its Known Exploited Vulnerabilities list due to evidence of active exploitation; Microsoft patched the issue in May 2023, and federal agencies must apply fixes by April 16, 2024. The report also references a demonstrated exploit chain combining CVE-2023-29357 and CVE-2023-24955, but no public details attribute active campaigns or specific threat actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
