LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-29357: Microsoft SharePoint Server Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 31, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-29357 to its Known Exploited Vulnerabilities catalog on Jan 10, 2024, with a federal patch deadline of Jan 31, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a…

CVE-2023-29357 is a privilege escalation vulnerability affecting Microsoft SharePoint Server. An unauthenticated attacker who has obtained spoofed JWT authentication tokens can use them to bypass authentication controls and obtain administrator privileges on the server.

This matters because the flaw enables full administrative control of SharePoint environments that host sensitive documents and collaboration data. Public reporting indicates the vulnerability has been used in ransomware operations, so organizations running SharePoint Server should prioritize assessment and remediation.

How it works

The issue is classified as CWE-303 and centers on improper handling of authentication material. According to the available summary, an attacker who has gained access to spoofed JWT authentication tokens can present those tokens in a network attack against SharePoint Server. The server accepts the tokens, authentication is bypassed, and the attacker is elevated to administrator privileges.

No further public detail is provided on the exact token-generation method, required network position, or precise request sequence. Defenders should treat the attack surface as any SharePoint endpoint that processes JWT-based authentication and must confirm the full technical description against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft SharePoint Server is typically deployed on-premises within enterprise Windows Server environments that provide intranet portals, document libraries, and collaboration services. Cloud-hosted SharePoint Online is outside the scope of this CVE.

How to remediate

Apply the security update supplied by Microsoft for this vulnerability as the primary remediation. Follow the installation and verification steps published in the vendor advisory; CISA directs organizations to apply mitigations per those instructions or to discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be installed, reduce risk with compensating controls:

If your data may have been exposed

Because this vulnerability has been exploited in ransomware campaigns, successful compromise can lead to data theft, encryption, or lateral movement. Review SharePoint content databases, recycle bins, and external sharing logs for unauthorized access. Organizations should also consider running a free exposure scan of their email addresses against known breach data sets to determine whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint Server
WeaknessCWE-303
Added to CISA KEVJan 10, 2024
Federal patch deadlineJan 31, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities