CVE-2023-24950 is a spoofing vulnerability affecting Microsoft SharePoint Enterprise Server and SharePoint Server. With a CVSS score of 6.5 (MEDIUM), it allows an authenticated attacker to achieve high confidentiality impact without user interaction, indicating a potentially significant data breach risk. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), its FAUCET Risk Score of 90/100 and mention in a BleepingComputer article suggest it warrants attention. Community discussion is limited, but the vulnerability was addressed in the Microsoft May 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_enterprise_server:2016:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:-:*:*:*:subscription:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.