CVE-2023-29357

Published Jun 14, 2023

Last updated 10 months ago

Overview

Description
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed
Products
sharepoint_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Microsoft SharePoint Server Privilege Escalation Vulnerability
Exploit added on
Jan 10, 2024
Exploit action due
Jan 31, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

secure@microsoft.com
CWE-303
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending
  1. 11 new OPEN, 15 new PRO (11 + 4) TA2730, Cisco UCM 15.x Unauth RCE, CVE-2023-29357 (MS Sharepoint Auth Bypass), CVE-2026-45659 (Sharepoint Deserialization RCE), Lumma Stealer, and many more. https://t.co/ejyHRbJocj

    @ET_Labs

    7 Aug 2026

    205 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Remote Code Execution (RCE)–CVE-2023-29357 https://t.co/XHmSWKSOMH via @LinkedIn Potential Impact Full server compromise Unauthorized access to sensitive data Malware or ransomware deployment Privilege escalation Lateral movement within the network Service disruption or data lo

    @Mania4Pakistan

    25 Jan 2026

    56 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Actively exploited CVE : CVE-2023-29357

    @transilienceai

    4 Aug 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. Still haven’t patched the SharePoint zero-day? CVE-2023-29357 is being exploited. If you run SharePoint Server (pre-2022), you’re exposed.

    @resiliencebrief

    29 Jul 2025

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2023-29357

    @transilienceai

    22 Apr 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. #letsdefend I investigated 'SOC227 - Microsoft SharePoint Server Elevation of Privilege - Possible CVE-2023-29357 Exploitation' incident on @LetsDefendIO

    @OluTechGuy

    4 Mar 2025

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Continuing with the Security Analyst Path on the @LetsDefendIO platform, we tackle an alert for an "Possible CVE-2023-29357 Exploitation". Was this simply a false positive or possibly something more unauthorized? https://t.co/UCkUpSxuiv

    @InfoSec_Bret

    21 Dec 2024

    43 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations