CVE-2023-29357CISA KEV
Microsoft SharePoint Server Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.
- Product
- SharePoint Server
- Added to KEV
- 10 Jan 2024
- Federal remediation due
- 31 Jan 2024
- Known ransomware use
- Yes