No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

CISA Adds 9.8 ‘Critical’ Microsoft SharePoint Bug to its KEV Catalog

January 15, 2024
in Protection
0
CISA Adds 9.8 'Critical' Microsoft SharePoint Bug to its KEV Catalog


On Wednesday, the Cybersecurity and Infrastructure Security Agency (CISA) added a privilege escalation vulnerability affecting Microsoft SharePoint servers to its list of Known Exploited Vulnerabilities (KEV).

SharePoint is a popular, cloud-based document management and storage system, which is also variously used by companies to implement internal applications and business processes, and share resources via an intranet. As recently as 2020, it enjoyed more than 200 million active monthly users.

The latest addition to KEV, CVE-2023-29357, is a “critical” 9.8 out of 10 vulnerability on the CVSS scale, affecting SharePoint Server 2016 and 2019. With no user engagement required, it allows an attacker to bypass authentication checks and gain administrative access to a server using spoofed JSON Web Token (JWT) authentication tokens.

Researchers first demonstrated the utility of CVE-2023-29357 at March 2023’s Pwn2Own event, combining it with a second SharePoint vulnerability to create a successful exploit chain — and winning $100,000 in the process. Another independent researcher developed a proof-of-concept (PoC) exploit in September.

Microsoft issued a patch back in June. However, it’s still being actively exploited, according to CISA’s new alert. In a Mastodon post on Thursday, security researcher Kevin Beaumont provided a bit of extra context, writing that “I am aware of one ransomware group that finally has a working exploit for this.”

For organizations still in the firing line, the June patch can be found here.



Editorial Team

Editorial Team

Related Posts

The Suunto Run Budget Running Watch Is Even Cheaper During Amazon's Big Spring Sale
Protection

The Suunto Run Budget Running Watch Is Even Cheaper During Amazon’s Big Spring Sale

March 26, 2026
Google's Pixel 9a Is Just $399 for the Amazon Big Spring Sale
Protection

Google’s Pixel 9a Is Just $399 for the Amazon Big Spring Sale

March 26, 2026
This Heart Rate Monitor Is Widely Regarded As the Best, and It’s 27% Off During Amazon’s Big Spring Sale
Protection

This Heart Rate Monitor Is Widely Regarded As the Best, and It’s 27% Off During Amazon’s Big Spring Sale

March 26, 2026
My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale
Protection

My Favorite JBL Over-Ear Headphones Are $100 Off During Amazon's Big Spring Sale

March 26, 2026
Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It's $140 Off During Amazon's Big Spring Sale
Protection

Artists Love the XP-Pen Magic Note Pad Drawing Tablet, and It’s $140 Off During Amazon’s Big Spring Sale

March 26, 2026
The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon's Big Spring Sale
Protection

The Garmin Forerunner 265 Is a Pretty Good Buy During Amazon’s Big Spring Sale

March 26, 2026
Load More
Next Post
3 Things All Retired Couples Should Know

3 Things All Retired Couples Should Know

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Yen under pressure after Takaichi report; Aussie higher on inflation

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0
  • The Best Luxury Hotels in Kansas City, Whether You’re Visiting for Barbecue or the World Cup

    0 shares
    Share 0 Tweet 0
  • What The Clarity Act Means For Ripple And XRP Once Done

    0 shares
    Share 0 Tweet 0

Latest News

Pollen Street reports strong private credit fundraising momentum

Pollen Street reports strong private credit fundraising momentum

March 26, 2026
0

Pollen Street reported sustained fundraising momentum across private credit and private equity in 2025, as total assets under management (AUM)...

The dash to cash has only just begun. Here’s what that means for stocks and bonds.

The dash to cash has only just begun. Here’s what that means for stocks and bonds.

March 26, 2026
0

Strategists at JPMorgan find the current buildup of cash by investors is nowhere near that which was seen after Russia’s...

The Suunto Run Budget Running Watch Is Even Cheaper During Amazon's Big Spring Sale

The Suunto Run Budget Running Watch Is Even Cheaper During Amazon’s Big Spring Sale

March 26, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Here’s why the crypto market is going down today

Here’s why the crypto market is going down today

March 26, 2026
0

The crypto market fell 2.5% on Friday to $2.45 trillion as hopes of an end to the ongoing U.S. Iran...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.