CVE-2023-29357

critical

Description

Microsoft SharePoint Server Elevation of Privilege Vulnerability

From the Tenable Blog

CVE-2023-29357, CVE-2023-24955: Exploit Chain Released for Microsoft SharePoint Server Vulnerabilities
CVE-2023-29357, CVE-2023-24955: Exploit Chain Released for Microsoft SharePoint Server Vulnerabilities

Published: 2023-09-27

A proof-of-concept exploit chain has been released for two vulnerabilities in Microsoft SharePoint Server that can be exploited to achieve unauthenticated remote code execution.

Microsoft’s June 2023 Patch Tuesday Addresses 70 CVEs (CVE-2023-29357)
Microsoft’s June 2023 Patch Tuesday Addresses 70 CVEs (CVE-2023-29357)

Published: 2023-06-13

Microsoft addresses 70 CVEs in its June 2023 Patch Tuesday update including six rated as critical.

References

Details

Source: Mitre, NVD

Published: 2023-06-14

Updated: 2026-06-17

Known Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99984