Back to Hub

Microsoft SharePoint Exploit Targets 90+ Government Entities Despite Patch

Imagen generada por IA para: Exploit en Microsoft SharePoint afecta a más de 90 entidades gubernamentales pese a parche

A previously patched vulnerability in Microsoft SharePoint is now at the center of a large-scale cyber campaign targeting government entities worldwide. Security researchers have confirmed attacks against over 90 state and local government organizations across North America, Europe, and Asia-Pacific regions.

The vulnerability, tracked as CVE-2023-29357, was originally patched by Microsoft in June 2023 as part of its monthly security updates. This privilege escalation flaw, with a CVSS score of 9.8 (Critical), allows attackers to gain administrator privileges on affected SharePoint servers without requiring authentication.

Technical Analysis:
The exploit chain involves:

  1. Spoofing JWT authentication tokens
  2. Bypassing SharePoint's security validation
  3. Executing remote code with SYSTEM privileges

Government systems appear particularly vulnerable due to:

  • Extended patch cycles (often 90+ days for validation)
  • Heavy reliance on SharePoint for sensitive document management
  • Complex hybrid environments (cloud/on-premises)

Mitigation Recommendations:

  1. Immediate application of June 2023 SharePoint security updates
  2. Network segmentation for SharePoint servers
  3. Multi-factor authentication enforcement
  4. Continuous monitoring for unusual admin account activity

The attacks follow a pattern of credential harvesting followed by data exfiltration, suggesting possible nation-state involvement. Microsoft has reiterated its guidance to apply all security updates promptly, especially for internet-facing systems.

Original sources

NewsSearcher

This article was generated by our NewsSearcher AI system, analyzing information from multiple reliable sources.

More than 90 state, local governments targeted using Microsoft SharePoint vulnerability, group says

Rappler
View source

Microsoft Vulnerability Sparks Major Government Security Alert

Devdiscourse
View source

⚠️ Sources used as reference. CSRaid is not responsible for external site content.

This article was written with AI assistance and reviewed by our editorial team.

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.