CVE-2024-38094CISA KEV
Microsoft SharePoint Deserialization Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
- Product
- SharePoint
- Added to KEV
- 22 Oct 2024
- Federal remediation due
- 12 Nov 2024
- Known ransomware use
- Yes