CVE-2023-29357

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
April 04, 2023
Published Date
June 13, 2023
Last Updated
February 04, 2025
Vendor
Microsoft
Product
Microsoft SharePoint Server 2019
Description
Microsoft SharePoint Server Elevation of Privilege Vulnerability

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2024-01-10 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2023-10-10 13:41:21 UTC) Source
Used in Malware
Yes (added 2024-01-10 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2024-01-10 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

Jev1337/CVE-2023-29357-Check

Type: github • Created: 2024-01-01 21:08:22 UTC • Stars: 2

A Python script that verifies whether a target is vulnerable to CVE-2023-29357 or not

KeyStrOke95/CVE-2023-29357-ExE

Type: github • Created: 2023-10-10 13:41:21 UTC • Stars: 2

Recreation of the SharePoint PoC for CVE-2023-29357 in C# from LuemmelSec

LuemmelSec/CVE-2023-29357

Type: github • Created: 2023-09-30 23:17:04 UTC • Stars: 52

Chocapikk/CVE-2023-29357

Type: github • Created: 2023-09-26 16:18:41 UTC • Stars: 231

Microsoft SharePoint Server Elevation of Privilege Vulnerability