Vulnerability record · CVE-2023-24950 · published 9 May 2023
CVE-2023-24950: Microsoft SharePoint Server spoofing via improper input validation
Microsoft · Sharepoint Enterprise Server
CVE-2023-24950 is a spoofing vulnerability in Microsoft SharePoint Server and SharePoint Enterprise Server, rooted in improper input validation (CWE-20). A network-reachable flaw of this class lets an attacker misrepresent content or identity to users, which matters because SharePoint is a trusted collaboration surface where spoofed pages or data can drive credential theft and downstream compromise. The record is thin: no affected version list, no attack mechanics, and no exploit detail are provided.
Description
Microsoft SharePoint Server Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityCVSS rates it medium (6.5) with confidentiality-only impact, but the very high EPSS score and the trusted nature of SharePoint justify prompt patching.
What it is
CVE-2023-24950 is a spoofing vulnerability in Microsoft SharePoint Server and SharePoint Enterprise Server, rooted in improper input validation (CWE-20). A network-reachable flaw of this class lets an attacker misrepresent content or identity to users, which matters because SharePoint is a trusted collaboration surface where spoofed pages or data can drive credential theft and downstream compromise. The record is thin: no affected version list, no attack mechanics, and no exploit detail are provided.
Impact
An authenticated attacker can spoof content or identity within SharePoint, potentially deceiving users into trusting manipulated pages or data. The CVSS vector shows high confidentiality impact only, with no integrity or availability effect recorded.
Attack surface
Reachable over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N), but it requires low privileges (PR:L), so the attacker needs a valid authenticated account. The description gives no further detail on the specific endpoint or input involved.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; the only references are Microsoft patch and vendor advisory links, with no public exploit or PoC tagged. EPSS is high at roughly 0.67 (99th percentile), indicating elevated predicted exploitation activity despite the absence of confirmed in-the-wild use.
What to do
- Apply the Microsoft security update for CVE-2023-24950 from the MSRC update guide as the first action.
- Restrict SharePoint access to accounts that genuinely need it and enforce least privilege to reduce the pool of authenticated attackers who can reach the flaw.
- Enable and review SharePoint audit logging and unified audit log to catch anomalous spoofing-related activity.
- Monitor Microsoft advisories for updated affected-version details, since this record does not list them.
Detection
- Review SharePoint audit logs for unusual page, list, or content modification events by low-privilege accounts.
- Hunt for user reports of unexpected or deceptive SharePoint content and correlate with authentication logs for the same accounts.
- Alert on anomalous authenticated access patterns to SharePoint endpoints from accounts that do not normally use them.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24950 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-24950 | PatchVendor Advisory |
Track CVE-2023-24950 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-24950), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.