critical
CISA KEV
Ransomware
CVE-2023-24955
Microsoft SharePoint Server Code Injection Vulnerability
Description
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Federal remediation due Apr 16, 2024 — past due
Advertisement