CVE-2023-24955 is a Microsoft SharePoint Server remote code execution vulnerability described as a code injection flaw. It allows an authenticated attacker with Site Owner privileges to execute arbitrary code on an affected SharePoint Server. Available reporting indicates exploitation involves SharePoint Business Connectivity Services and the Business Data Catalog path, where a crafted BDCM model can be uploaded and the vulnerable behavior triggered through SharePoint client service requests. The issue has also been described as part of exploit chains with CVE-2023-29357, in which spoofed JWT-based authentication bypass is used first to obtain the privileges needed to reach this code execution condition.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting Microsoft SharePoint Server 2019, specifically exploiting a pre-authentication chain involving CVE-2023-29357 (authentication bypass) and CVE-2023-24955 (remote code execution). The exploit works by first bypassing authentication via a flaw in JWT signature validation, allowing the attacker to impersonate the SharePoint admin. With admin privileges, the module then abuses the SharePoint API to replace the BDCMetadata.bdcm file with a payload, which is subsequently executed by the server, resulting in arbitrary command execution. The module is weaponized, supporting customizable payloads (defaulting to a Meterpreter reverse shell) and includes logic to restore the original file after exploitation. The main attack vector is network-based, targeting the SharePoint HTTP(S) interface. The code is written in Ruby and is structured as a standard Metasploit exploit module, with clear separation of authentication bypass, payload delivery, and cleanup routines. No hardcoded IPs or external domains are present; all endpoints are relative to the target SharePoint server.
This repository contains a Python 2 exploit script (CVE-2023-24955.py) and a README.md. The exploit targets Microsoft SharePoint 2019 servers vulnerable to CVE-2023-24955, a remote code execution vulnerability. The script performs several steps: it authenticates to the SharePoint server using NTLM, manipulates SharePoint's Business Data Connectivity Metadata (BDCM), and uploads a malicious .aspx web shell to a path under /_vti_bin/DelveApi.ashx/gift_from_starlabs/. The web shell allows the attacker to execute arbitrary commands on the server. The script requires Python 2 and logs its activity to debug.log. The README provides usage instructions and notes that the script is a fixed version of a previously published PoC. The exploit is operational, providing a working web shell if the target is vulnerable. No framework is used; the code is standalone.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior SharePoint code injection remote code execution vulnerability referenced as a historical comparison because it similarly abused BDC model upload and processing.
A Microsoft SharePoint Server remote code execution vulnerability that allows an authenticated Site Owner to execute code; used as the code-execution step in a demonstrated exploit chain with CVE-2023-29357 to achieve unauthenticated RCE.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.