← לוח פגיעויות

CVE-2023-24955

גבוהה 7.2 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft SharePoint Server Code Injection Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Microsoft SharePoint Server Remote Code Execution Vulnerability

מדדים

CVSS 3.1
7.2 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
85% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-94

מוצרים מושפעים

microsoft: sharepoint enterprise server; microsoft: sharepoint server

קישורים