HIGH
CVE-2024-38094
CVSS
7.2
KEV
Description
Microsoft SharePoint Remote Code Execution Vulnerability
Summary dbcve.org
This is an authenticated Remote Code Execution vulnerability in Microsoft SharePoint. An attacker who has permissions on a vulnerable SharePoint site could execute arbitrary code on the server by sending specially crafted requests.
Mitigation
Apply Microsoft security updates for SharePoint Server. Ensure SharePoint installations are fully patched. Limit SharePoint site permissions to minimum required principles.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
50.89%
Probability of exploitation in next 30 days
98.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.