CVE-2023-29357 is a critical Elevation of Privilege vulnerability affecting Microsoft SharePoint Server, allowing unauthenticated attackers to bypass authentication and gain administrative privileges. With a CVSS score of 9.8, it is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability is actively exploited, including in known ransomware campaigns, with public exploit code available in Metasploit and Nuclei templates, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.