Lucene search

K
hiveproHiveForce LabsHIVEPRO:2339F2558BCE57A6172B07E8A0E7E0D8
HistoryJan 15, 2024 - 12:56 p.m.

Active Exploitation of Two Critical Flaws in Microsoft SharePoint

2024-01-1512:56:34
HiveForce Labs
www.hivepro.com
13
microsoft sharepoint
active exploitation
cve-2023-29357
privilege escalation
administrator access
cve-2023-24955
arbitrary code execution
patching
june 2023
patch tuesday
threat level red

8.3 High

AI Score

Confidence

Low

0.89 High

EPSS

Percentile

98.8%

Summary: Active attacks targeting a critical Microsoft SharePoint Server vulnerability (CVE-2023-29357) pose a severe risk, enabling privilege escalation for potential full administrator access. This flaw, coupled with CVE-2023-24955, allows arbitrary code execution. Immediate patching is crucial, as fixes have been available since June 2023's Patch Tuesday. Threat Level - Red | Vulnerability Report For a detailed threat advisory, download the pdf file here To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.