{"cvss":9.8,"datePublished":"2024-01-10","dateUpdated":"2024-01-10","description":"Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.","dueDate":"2024-01-31","id":"CVE-2023-29357","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357; https://nvd.nist.gov/vuln/detail/CVE-2023-29357","product":"SharePoint Server","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Microsoft SharePoint Server Privilege Escalation Vulnerability","vendor":"Microsoft"}