CISA is warning of a critical privilege escalation vulnerability in Microsoft SharePoint thatcould be exploited in conjunction with another critical flaw and lead to remote code execution.

The vulnerability in Microsoft SharePoint is tracked as CVE-2023-29357 and allows remote attackers to gain administrative privileges on unpatched servers bypassing authentication by (using forged JWT auth tokens).
“ An attacker who has gained access to spoofed JWT authentication tokens can use them to perform a network attack that bypasses authentication and allows them to gain access to the privileges of an authenticated user ,” Microsoft explains
See also: Serious vulnerability in Bosch smart thermostats
The company also says that successful exploitation of the vulnerability could allow an attacker to gain administrator privileges. Furthermore, no user interaction is required.
Remote attackers can also execute code on compromised SharePoint servers via command injection when they combine this bug with the SharePoint Server vulnerability, CVE-2023-24955, which allows remote code execution.
This Microsoft SharePoint Server exploit chain was presented by STAR Labs researcher Jang (Nguyễn Tiến Giang) during the last Pwn2Own in March 2023. The researcher published a technical analysis on September 25 detailing the exploit process.
Just a day later, another researcher also released a proof-of-concept exploit for the Microsoft SharePoint vulnerability CVE-2023-29357 on GitHub.
This exploit did not provide remote code execution on targeted systems, but the researcher said that attackers could combine it with the CVE-2023-24955 flaw to achieve the same purpose.
“The script extracts details of admin users with elevated privileges and can operate in both single and mass exploitation mode,” says the developer of the PoC exploit.
See also: POST SMTP Mailer: Vulnerabilities in WordPress plugin – Update immediately!
“However, to maintain an ethical stance, this script does not contain any functions to perform RCE and is intended solely for educational purposes and legal and authorized testing“.
Since then, other PoC exploits for the vulnerability and the connection of vulnerabilities have been released, allowing more and more cybercriminals to deploy it in attacks.
While it has not yet provided additional details about the active exploit CVE-2023-29357, CISA has added the vulnerability to the List of Known Exploitable Vulnerabilities and is requiring U.S. federal agencies to patch it by January 31. Alternatively, they will have to stop using the vulnerable systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection from vulnerabilities
The most basic way to protect against vulnerabilities is to update systems with the latest security patches that address the issues.
Additionally, one of the latest trends in combating privilege escalation and remote code execution vulnerabilities is the use of artificial intelligence and machine learning. These technologies help automate the process of detecting and preventing attacks.
See also: Android: Security update fixes 58 vulnerabilities
Also, the use of Vulnerability Management Systems is becoming increasingly popular. These systems provide continuous monitoring and reporting of vulnerabilities present in an organization's network.
Finally, the implementation of the Principle of Least Privilege (PoLP) policy is another important trend. This policy limits users to the minimum necessary to perform their tasks, thereby reducing the opportunity for privilege escalation.
Source: www.bleepingcomputer.com
