CVE-2023-24954HighCVSS 6.5

Microsoft SharePoint Server Information Disclosure Vulnerability

Published
May 9, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is user tokens and other potentially sensitive information.

According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability? A successful attacker could gain the Domain SID prefix for the targeted site.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? The attacker must be authenticated to be able to exploit this vulnerability.

🎯 Affected products3

  • Microsoft SharePoint Enterprise Server 2016
  • Microsoft SharePoint Server 2019
  • Microsoft SharePoint Server Subscription Edition

✅ Remediation

KB5002397 (Security Update) — fixed build 16.0.5395.1000 KB5002389 (Security Update) — fixed build 16.0.10398.20000 KB5002390 (Security Update) — fixed build 16.0.16130.20420

🔗 References (7)