Vulnerability record · CVE-2023-21742 · published 10 January 2023
CVE-2023-21742: Microsoft SharePoint Server improper access control leads to remote code execution
Microsoft · Sharepoint Foundation
CVE-2023-21742 is a remote code execution vulnerability in Microsoft SharePoint Foundation and SharePoint Server, classified as improper access control (CWE-284) with insufficient detail on the exact mechanism. It matters because a network-reachable SharePoint deployment can be compromised by a low-privileged authenticated user without any user interaction, and the record gives no further root-cause detail.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable remote code execution with high EPSS despite no KEV listing or documented exploit makes this a high-priority patch for exposed SharePoint servers.
What it is
CVE-2023-21742 is a remote code execution vulnerability in Microsoft SharePoint Foundation and SharePoint Server, classified as improper access control (CWE-284) with insufficient detail on the exact mechanism. It matters because a network-reachable SharePoint deployment can be compromised by a low-privileged authenticated user without any user interaction, and the record gives no further root-cause detail.
Impact
An attacker who can authenticate to SharePoint gains code execution on the server, with high impact to confidentiality, integrity and availability. That typically means full control of the SharePoint host and any data or credentials it can reach.
Attack surface
Reached over the network via the SharePoint web interface (AV:N), requiring only low privileges (PR:L) and no user interaction (UI:N). No public exploit or pre-auth path is documented in this record.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is 0.55786 (99th percentile), indicating a high predicted likelihood of exploitation activity. The two references are both the Microsoft update guide with no exploit tags.
What to do
- Apply the Microsoft security update for CVE-2023-21742 to all affected SharePoint Foundation and SharePoint Server instances as the first action.
- Restrict and audit who holds authenticated access to SharePoint sites, since exploitation requires only low privileges.
- Segment SharePoint servers from other internal systems and limit outbound access to reduce post-exploitation reach.
- Monitor Microsoft advisories for updated guidance, as the record provides no workaround detail.
Detection
- Review SharePoint IIS and ULS logs for anomalous requests or w3wp.exe spawning child processes such as cmd.exe or powershell.exe.
- Alert on unexpected file writes or new web shells under SharePoint web directories.
- Baseline and monitor authentication events for low-privileged accounts performing unusual server-side operations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-21742 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21742), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.