Microsoft SharePoint Server Code Injection Vulnerability
Microsoft · SharePoint Server
Date added (CISA)
2024-03-26
Remediation due
2024-04-16
Known ransomware use
Yes
Remediation priority
P1 — known ransomware use · past CISA due date
Description
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.