ZeroFox Intelligence Flash Report - Critical Microsoft SharePoint Vulnerability Actively Exploited
|by Alpha Team

ZeroFox Intelligence Flash Report - Critical Microsoft SharePoint Vulnerability Actively Exploited
Product Serial: F-2024-01-15a
TLP:CLEAR
In this flash report, ZeroFox researchers report on a critical severity Microsoft SharePoint privilege escalation vulnerability currently being actively exploited in the wild.
Standing Intelligence Requirements
Deep Dark Web and Criminal Underground

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- Critical severity Microsoft SharePoint privilege escalation vulnerability CVE-2023-29357 has been added to the U.S. Cybersecurity & Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities Catalog, indicating it is being actively exploited in cyber attacks.
- The vulnerability can be exploited alongside Remote Code Execution (RCE) vulnerability CVE-2023-24955, forming an attack chain able to further compromise the confidentiality, integrity, and availability of a target system.
- ZeroFox urges users to ensure networks are patched with the latest Microsoft software updates.
Tags: tlp:clear, dark web, vulnerability/exploit, threat actor