CVE-2023-29357

CRITICAL KEV RANSOMWARE NUCLEI

Sharepoint Dynamic Proxy Generator Unauth RCE

Title source: metasploit

Description

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Exploits (8)

nomisec WORKING POC 235 stars
by Chocapikk · remote
https://github.com/Chocapikk/CVE-2023-29357
nomisec WORKING POC 53 stars
by LuemmelSec · remote
https://github.com/LuemmelSec/CVE-2023-29357
nomisec SUSPICIOUS 4 stars
by Guillaume-Risch · poc
https://github.com/Guillaume-Risch/cve-2023-29357-Sharepoint
nomisec SUSPICIOUS 2 stars
by KeyStrOke95 · poc
https://github.com/KeyStrOke95/CVE-2023-29357-ExE
nomisec SCANNER 1 stars
by Jev1337 · remote
https://github.com/Jev1337/CVE-2023-29357-Check
nomisec WORKING POC
by DonVorrin · remote
https://github.com/DonVorrin/CVE-2023-29357
nomisec WRITEUP
by DeividasTerechovas · poc
https://github.com/DeividasTerechovas/SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation
nomisec NO CODE
by AhmedMansour93 · poc
https://github.com/AhmedMansour93/Event-ID-189-Rule-Name-SOC227-CVE-2023-29357

Nuclei Templates (1)

Microsoft SharePoint - Authentication Bypass
CRITICALVERIFIEDby pdteam
Shodan: http.headers_hash:-1968878704 || cpe:"cpe:2.3:a:microsoft:sharepoint_server"
FOFA: app="Microsoft-SharePoint" || app="microsoft-sharepoint"

Scores

CVSS v3 9.8
EPSS 0.9436
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2024-01-10
VulnCheck KEV 2023-11-16
InTheWild.io 2024-01-10
ENISA EUVD EUVD-2023-32930
Ransomware Use Confirmed
CWE
CWE-303
Status published
Products (1)
microsoft/sharepoint_server 2019
Published Jun 14, 2023
KEV Added Jan 10, 2024
Tracked Since Feb 18, 2026