Sept. 19, 2023, 1:37 p.m. | /u/netlas_io

cybersecurity www.reddit.com

**Main information**

CVE: CVE-2023-36764Vulnerable product: Mirosoft SharePoint ServerBase score: 8.8 (High)

**In detail**

This vulnerability was discovered by Microsoft.Some SharePoint servers are vulnerable to Elevation of Privelege. Attacker could gain administrator privileges by creating an ASP.NET page with specially-crafted declarative markup. Only authorization at the Site Member level is required.

**Timeline**

CVE was published at 09/12/2023.Patch was uploaded at 09/12/2023.Vulnerability didn’t exploited before patch.

**Quantity estimation**

[Shodan – 2,572 instances](https://www.shodan.io/search?query=http.component%3A%22Microsoft+SharePoint%22)

Dork: http.component:"Microsoft SharePoint"

[Censys – 16,956 instances](https://search.censys.io/search?resource=hosts&sort=RELEVANCE&per_page=25&virtual_hosts=EXCLUDE&q=labels%3D%60microsoft-sharepoint%60)

Dork: labels=\`microsoft-sharepoint\`

[Netlas …

asp attacker authorization cve cybersecurity high information main markup microsoft microsoft sharepoint mirosoft .net page privileges product score server servers sharepoint stats timeline vulnerability vulnerable

Business Information Security Officer

@ Metrolink | Los Angeles, CA

Senior Security Engineer

@ Freedom of the Press Foundation | Remote, 4 hour time zone overlap with New York City

Security Engineer

@ ChartMogul | Remote, EU

Cyber Hunt Subject Matter Expert (SME) - Hybrid

@ XOR Security | Alexandria, VA

Software Compliance, Safety and Security Manager (w/m/d)

@ Bosch Group | Stuttgart, Germany

Chef de projet - Service PKI

@ Alter Solutions | Paris, France