CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability

High severity, CVSS 7.2. Actively exploited: in CISA KEV since 2024-03-26. EPSS: 85% chance of exploitation in the next 30 days.

Microsoft SharePoint Server Remote Code Execution Vulnerability

Affected products

  • Microsoft SharePoint Enterprise Server: version 2016 only
  • Microsoft SharePoint Server: affected versions not specified; version 2019 only

Published 2023-05-09. Last modified 2026-06-17.