CISA has added a serious vulnerability affecting Microsoft SharePoint to its Known Exploited Vulnerabilities (KEV) list .

The vulnerability, which is tracked as CVE-2024-38094 (CVSS score: 7.2), is a vulnerability , affecting SharePoint and could allow remote code execution.
According to Microsoft, an authorized attacker with Site Owner privileges could use the vulnerability to inject arbitrary code. They could then execute that code within the SharePoint Server context.
See also: CISA added ScienceLogic SL1 vulnerability to KEV Catalog
The company fixed the vulnerability via Patch Tuesday in July 2024.However, those who have not applied the updates are at risk. In fact, PoC exploits for the vulnerability, which makes things even more dangerous.
“ The PoC script […] automates authentication to the target SharePoint site using NTLM, creates a specific folder and file , and sends a crafted XML payload to trigger the vulnerability in the SharePoint client API ,” SOCRadar said .
There are currently no reports on how attackers are exploiting CVE-2024-38094.
According to CISA, Federal Civilian Executive Branch (FCEB) agencies are required to implement the latest updates by November 12, 2024 , to secure their networks.
See also: CISA: Adds SolarWinds WHD vulnerability to KEV List

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.
The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA helps a lot in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, state governments, and local authorities, to improve the security of digital systems.
See also: CISA: Adds new Ivanti EPM vulnerability to KEV List
It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Overall, CISA's role is vital to protecting the digital infrastructure of the US and other regions.
Source: thehackernews.com
