HIGH
CVE-2023-24955
CVSS
7.2
KEV
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
Summary dbcve.org
A remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code on the affected server, potentially leading to complete system compromise.
Mitigation
Apply Microsoft security updates for SharePoint Server (cumulative updates or specific security patches) and follow Microsoft guidance for SharePoint Server patch deployment.
Weakness (CWE)
CWE-94
Code Injection
EPSS Score
85.4%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.