CVE-2023-24955CriticalCVSS 7.2
Microsoft SharePoint Server Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
How could an attacker exploit the vulnerability? In a network-based attack, an authenticated attacker as a Site Owner could execute code remotely on the SharePoint Server.
🎯 Affected products3
- Microsoft SharePoint Enterprise Server 2016
- Microsoft SharePoint Server 2019
- Microsoft SharePoint Server Subscription Edition
✅ Remediation
KB5002397 (Security Update) — fixed build 16.0.5395.1000 KB5002389 (Security Update) — fixed build 16.0.10398.20000 KB5002390 (Security Update) — fixed build 16.0.16130.20420
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955
- patchhttps://www.microsoft.com/download/details.aspx?familyid=7a299fb3-33f2-4417-809d-7bf31da6d14e
- referencehttps://support.microsoft.com/help/5002397
- patchhttps://www.microsoft.com/download/details.aspx?familyid=c9190144-e85b-4ded-9b6f-cc9b295054f3
- referencehttps://support.microsoft.com/help/5002389
- patchhttps://www.microsoft.com/download/details.aspx?familyid=1aac4804-a1a0-4d40-8d9a-a1ac25def0b0
- referencehttps://support.microsoft.com/help/5002390