CISA tags Microsoft SharePoint RCE bug as actively exploited

March 27, 2024 at 12:30PM CISA warns of attackers exploiting a Microsoft SharePoint vulnerability, enabling remote code execution and admin privilege takeover. Nguyễn Tiến Giang earned $100,000 for demonstrating its exploitation. Multiple proof-of-concept exploits have emerged, prompting CISA to order patching by January 31. This poses a significant risk, emphasizing the need for quick patching … Read more

CISA Warns: Hackers Actively Attacking Microsoft SharePoint Vulnerability

March 27, 2024 at 10:09AM The US Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw in Microsoft SharePoint Server, CVE-2023-24955, to its Known Exploited Vulnerabilities catalog. The flaw allows authenticated attackers with Site Owner privileges to execute arbitrary code. Federal agencies must apply the fixes by April 16, 2024, to secure … Read more