LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 26, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Apr 16, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-24955 to its Known Exploited Vulnerabilities catalog on Mar 26, 2024, with a federal patch deadline of Apr 16, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.

CVE-2023-24955 is a code injection vulnerability in Microsoft SharePoint Server. An authenticated attacker who already holds Site Owner privileges can abuse it to execute code remotely on the server. Because SharePoint often stores sensitive collaboration data and is a common target for ransomware operators, this flaw matters for any organization running on-premises SharePoint Server. Confirm all version and patch details against the official Microsoft advisory.

CISA notes that the vulnerability has been used in ransomware campaigns and requires organizations to apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

How it works

The underlying weakness is CWE-94 (code injection). In this class of flaw, an application fails to properly validate or sanitize input that is later treated as executable code. According to the CISA summary, an attacker who already possesses Site Owner privileges on a SharePoint Server instance can inject malicious code that the server then executes with the privileges of the SharePoint process. The attack therefore requires authentication and elevated SharePoint rights; it is not a remote unauthenticated exploit. Exact injection vectors and payloads are not detailed in the public summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft SharePoint Server is typically deployed on-premises as a collaboration and document-management platform, often integrated with Active Directory and exposed to internal users or via reverse proxies. Inventory every SharePoint Server farm, including development, staging, and production instances. Check the installed product version and cumulative update level against the Microsoft security advisory for CVE-2023-24955; only the advisory lists the precise builds that are vulnerable or fixed.

Telemetry signs of exploitation are not exhaustively published; treat any unexplained remote code execution under SharePoint service accounts as suspicious and escalate for forensic review.

How to remediate

Patch first. Apply the security update Microsoft released for this vulnerability, following the exact guidance and prerequisites listed in the vendor advisory. After installation, verify the new build number and restart the relevant SharePoint services. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Beyond the patch, harden the SharePoint environment for this class of issue:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities of this type have been leveraged by ransomware groups. If you discover evidence of compromise, isolate affected servers, preserve logs, and engage incident-response procedures. Review SharePoint content and permissions for unauthorized changes. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint Server
WeaknessCWE-94
Added to CISA KEVMar 26, 2024
Federal patch deadlineApr 16, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities