CVE-2023-24955
HIGH KEV RANSOMWAREMicrosoft SharePoint Server - Remote Code Execution
Title source: llmExploitation Summary
CVE-2023-24955 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added March 26, 2024, with confirmed use in ransomware campaigns.
EIP tracks 2 public exploits from researchers including former-farmer, Jang, jheysel-r7, including a Metasploit module exploits/windows/http/sharepoint_dynamic_proxy_generator_auth_bypass_rce.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-24955, targeting SharePoint Server 2019. The exploit leverages NTLM authentication and token manipulation to achieve remote code execution (RCE) by injecting malicious code into a memory-based web shell.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
Exploits (2)
This repository contains a functional exploit for CVE-2023-24955, targeting SharePoint Server 2019. The exploit leverages NTLM authentication and token manipulation to achieve remote code execution (RCE) by injecting malicious code into a memory-based web shell.
This Metasploit module exploits CVE-2023-29357 (auth bypass via JWT 'none' algorithm) and CVE-2023-24955 (RCE via file replacement) in SharePoint 2019. It impersonates the SharePoint admin and executes commands via API.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H