"Ransomware Crew Reportedly Exploiting Critical Microsoft SharePoint Bug, CISA Warns"

1 min read
Source: BleepingComputer
"Ransomware Crew Reportedly Exploiting Critical Microsoft SharePoint Bug, CISA Warns"
Photo: BleepingComputer
TL;DR Summary

CISA warns of active exploitation of a critical Microsoft SharePoint privilege escalation vulnerability (CVE-2023-29357) that allows attackers to gain admin privileges by spoofing JWT auth tokens. This flaw can be chained with another critical bug (CVE-2023-24955) for remote code execution. A proof-of-concept exploit has been released on GitHub, and other PoC exploits have surfaced online, making it easier for threat actors to deploy attacks. CISA has added the vulnerability to its Known Exploited Vulnerabilities Catalog and mandated U.S. federal agencies to patch it by January 31.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

1 min

vs 2 min read

Condensed

76%

35586 words

Want the full story? Read the original article

Read on BleepingComputer