Security Snippets: Microsoft SharePoint vulnerability to watch out for

Hogan Lovells
Contact

Hogan Lovells[co-author: Rachel Dalton]

A vulnerability in Microsoft SharePoint has been flagged as being actively exploited by CISA.


A vulnerability in Microsoft SharePoint is being actively exploited according to CISA’s known exploited vulnerabilities (KEV) catalogue. This defect, tracked as CVE-2023-29357, is an elevation of privilege flaw—it allows for threat actors to gain administrator privileges in the SharePoint servers. User interaction does not appear to be required for successful exploitation under this vulnerability. NIST gave CVE-2023-29357 a severity score of 9.8 out of 10.

Microsoft was aware of CVE-2023-29357 and released a patch in June of 2023. However, some SharePoint servers are not receiving automatic updates or might have otherwise fallen through the cracks. It may be helpful for security teams to confirm that they have no unpatched instances of SharePoint in their environments. CISA recommends patching the vulnerability by January 31, 2024 in order to secure against the active threat.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Hogan Lovells | Attorney Advertising

Written by:

Hogan Lovells
Contact
more
less

Hogan Lovells on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide