LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-38094: Microsoft SharePoint Deserialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 22, 2024
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 12, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-38094 to its Known Exploited Vulnerabilities catalog on Oct 22, 2024, with a federal patch deadline of Nov 12, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

CVE-2024-38094 is a deserialization vulnerability in Microsoft SharePoint that enables remote code execution. Attackers who can reach a vulnerable SharePoint instance may run arbitrary code on the underlying server, which can lead to full system compromise, data theft, or further lateral movement. CISA notes that this issue has been used by ransomware operators, so organizations running SharePoint should treat it as a high-priority risk and confirm current status against the vendor advisory.

How it works

The flaw belongs to CWE-502 (Deserialization of Untrusted Data). SharePoint processes serialized objects; when those objects come from an untrusted source and are not properly validated, an attacker can craft malicious input that the application deserializes into executable objects. Successful abuse results in remote code execution under the privileges of the SharePoint process. Exact request formats, endpoints, or payload construction are not detailed in the public summary and must be verified against Microsoft’s advisory; defenders should assume any unauthenticated or low-privilege network access to SharePoint services could be sufficient for exploitation of this class of issue.

Am I affected? How to find it in your systems

Microsoft SharePoint is commonly deployed as on-premises server farms, hybrid configurations, or SharePoint Server instances supporting collaboration, document management, and intranet portals. Inventory every SharePoint installation by querying Active Directory for SharePoint-related service accounts, scanning for the SharePoint Central Administration site, reviewing installed Microsoft server products via inventory tools, and examining web-server roles that host SharePoint web applications.

Any SharePoint environment reachable from untrusted networks should be treated as potentially exposed until proven otherwise.

How to remediate

Apply the security update provided by Microsoft for this CVE as the primary remediation. Follow the vendor’s installation guidance exactly, including any required restarts or configuration steps. After patching, verify the update is present by checking the product’s build number or update history against the advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities of this type frequently lead to ransomware deployment and data breaches. If compromise is suspected, isolate affected servers, preserve forensic evidence, and follow your incident-response plan. Organizations can also run a free exposure scan of their email addresses against known breach data sets to determine whether credentials or other information associated with the environment have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · SharePoint
WeaknessCWE-502
Added to CISA KEVOct 22, 2024
Federal patch deadlineNov 12, 2024
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities