CVE-2023-24955CISA KEV
Microsoft SharePoint Server Code Injection Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
- Product
- SharePoint Server
- Added to KEV
- 26 Mar 2024
- Federal remediation due
- 16 Apr 2024
- Known ransomware use
- Yes