PT-2024-4782 · Microsoft · Sharepoint Server

Cjm00N

+3

·

Published

2024-07-09

·

Updated

2025-11-24

·

CVE-2024-38024

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified)
Description This issue involves flaws in the deserialization mechanism within Microsoft SharePoint Server. Successful exploitation could allow a remote attacker to execute arbitrary code by uploading a specially crafted file. The vulnerability requires authentication to exploit.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05305
CVE-2024-38024
ZDI-24-1534

Affected Products

Sharepoint Server