CVE-2023-24955Active Exploitation(microsoft / sharepoint_enterprise_server)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft sharepoint_enterprise_server systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Microsoft SharePoint Server Remote Code Execution Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-04-16. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_enterprise_server
  • sharepoint_server

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-05-18); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
sharepoint_enterprise_serversharepoint_server

3 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-18: 1Mentions · 2026-06-24: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-05-18: 105-1806-24
Signal classification1 categories
Active Exploitation
2100.0%
Full discourse2 posts
  • CyDhaal@CyberDhaal
    Active Exploitation

    2/3 Current attack pattern: • Initial access via unpatched CVEs (including CVE-2023-29357 & CVE-2023-24955) • Custom web shells dropped in sensitive directories (/_layouts/, /_catalogs/, /_vti_bin/) • Privilege escalation using SharePoint service accounts • Lateral movement + ransomware deployment via scheduled tasks or Group Policy • Heavy targeting of healthcare, finance, legal, and government environments Many organizations still run exposed SharePoint 2016/2019/Subscription Edition instances.

    Post summary

    The message outlines ongoing attacks exploiting unpatched SharePoint CVEs in targeted sectors, with no PoC, patch, or detailed vulnerability info provided.

    1000057
    510 followersView on X
  • ZeroDay Post@ZeroDayPost
    Active Exploitation

    7/ Heads up, sysadmins: CISA added a critical Microsoft SharePoint RCE bug (CVE-2023-24955) to its Known Exploited Vulnerabilities catalog. It's being actively used in attacks. Patching is urgent.

    Post summary

    Microsoft SharePoint RCE (CVE-2023-24955) is actively exploited, with CISA marking it as a known vulnerable issue and urging immediate patching.

    1000084
    5 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_enterprise_server2016--
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2019--

Explore more