Sept. 19, 2023, 1:37 p.m. | /u/netlas_io

cybersecurity www.reddit.com

**Main information**

CVE: CVE-2023-36764Vulnerable product: Mirosoft SharePoint ServerBase score: 8.8 (High)

**In detail**

This vulnerability was discovered by Microsoft.Some SharePoint servers are vulnerable to Elevation of Privelege. Attacker could gain administrator privileges by creating an ASP.NET page with specially-crafted declarative markup. Only authorization at the Site Member level is required.

**Timeline**

CVE was published at 09/12/2023.Patch was uploaded at 09/12/2023.Vulnerability didn’t exploited before patch.

**Quantity estimation**

[Shodan – 2,572 instances](https://www.shodan.io/search?query=http.component%3A%22Microsoft+SharePoint%22)

Dork: http.component:"Microsoft SharePoint"

[Censys – 16,956 instances](https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=EXCLUDE&q=labels%3D%60microsoft-sharepoint%60)

Dork: labels=\`microsoft-sharepoint\`

[Netlas …

asp attacker authorization cve cybersecurity high information main markup microsoft microsoft sharepoint .net page privileges product score server servers sharepoint stats timeline vulnerability vulnerable

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)