{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-24955",
  "revision": 1,
  "title": "SharePoint Server — a site owner who can inject code",
  "summary": "An account holding site owner rights in Microsoft SharePoint Server injects code that the server then runs. Microsoft publishes nothing beyond the class of flaw, and ransomware operations are known to use it.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.2,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.85395,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2024-03-26",
    "prerequisites": "The attacker must hold site owner rights on the SharePoint site."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1059"
  ],
  "kill_chain": "execution",
  "recommended_action": "Install the May 2023 SharePoint Server update, then review who holds site owner rights — that role is the entire precondition for this one.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-24955",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-24955",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-24955",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24955",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24955"
    }
  ],
  "published_at": "2023-05-09T18:15:13.317Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "microsoft",
    "sharepoint",
    "code-injection",
    "ransomware",
    "kev"
  ]
}
