Cyber Security News

Microsoft SharePoint Server Vulnerabilities Chained to Achieve Remote Code Execution

Microsoft SharePoint Server was reported with two vulnerabilities, CVE-2023-29357 and CVE-2023-24955, which threat actors can use for achieving remote code execution (RCE) against Microsoft SharePoint Server.

These vulnerabilities were discovered as part of the Zero Day Initiative’s Pwn2Own contest conducted in March 2023. The STAR labs team was able to find this vulnerability and were rewarded $100,000 for their finding.

However, security researcher Nguyễn Tiến Giang published a GitHub repository containing the proof-of-concept (PoC) for the exploit chain, which could chain these two vulnerabilities to achieve successful remote command execution.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

CVE-2023-29357 & CVE-2023-24955 – Technical Analysis

CVE-2023-29357 was a Privilege Escalation vulnerability that existed on the Microsoft SharePoint Server, which threat actors can exploit by sending a spoofed JWT (JSON Web Token) authentication token to the Microsoft SharePoint Server, which could elevate their privileges. This vulnerability had a severity of 9.8 (Critical). 

CVE-2023-24955 was a Remote Command Execution vulnerability affecting the same Microsoft SharePoint Server and had a severity of 7.2 (High). Microsoft patched both of these vulnerabilities as part of their May and June security patches.

Exploit Chain

After conducting several research for over a year, security researcher Jang combined the authentication bypass vulnerability with the code injection vulnerability, which resulted in an unauthenticated RCE on the Microsoft SharePoint Server. A Proof-of-concept video was also published, which demonstrated the attack and exploitation. 

Additionally, it was worth noting that the security researchers made sure that the publicly available proof-of-concept does not achieve unauthenticated RCE, as threat actors can indulge in various malicious activities with a publicly available exploit.

Users of the Microsoft SharePoint server are recommended to patch these vulnerabilities by following the Microsoft Security patch released every second Tuesday of every month.

Protect yourself from vulnerabilities using Patch Manager Plus to quickly patch over 850 third-party applications. Take advantage of the free trial to ensure 100% security.

Eswar

Eswar is a Cyber security reporter with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is reporting data breach, Privacy and APT Threats.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

4 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

10 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

21 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago