Vulnerability record · CVE-2024-30044 · published 14 May 2024
CVE-2024-30044: Microsoft SharePoint Server deserialization remote code execution
Microsoft · Sharepoint Server
CVE-2024-30044 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It matters because a successful exploit gives full control over the affected server's confidentiality, integrity and availability, and the EPSS score places it among the most likely vulnerabilities to be exploited in the near term.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution with full impact on a widely deployed server product and a very high EPSS probability, though exploitation requires privileged access and no KEV listing or public exploit is confirmed.
What it is
CVE-2024-30044 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It matters because a successful exploit gives full control over the affected server's confidentiality, integrity and availability, and the EPSS score places it among the most likely vulnerabilities to be exploited in the near term.
Impact
An attacker who exploits the flaw can execute arbitrary code on the SharePoint server, gaining the ability to read or alter data and disrupt service. The CVSS impact ratings for confidentiality, integrity and availability are all High.
Attack surface
The vulnerability is network-reachable (AV:N) with no user interaction (UI:N), but the CVSS vector requires High privileges (PR:H), meaning the attacker must already hold an administrative or otherwise privileged SharePoint account. No other access path is described in the record.
Exploitation
CVE-2024-30044 is not listed in CISA KEV and has no documented ransomware use, but its EPSS 30-day probability of 0.8399 (99.7th percentile) indicates a high likelihood of exploitation. The only references are Microsoft vendor advisories, so no public exploit details are confirmed in this record.
What to do
- Apply the Microsoft security update for CVE-2024-30044 as soon as possible.
- Restrict and audit privileged SharePoint accounts, since exploitation requires High privileges.
- Limit network exposure of SharePoint servers and enforce MFA on administrative access.
- Monitor for unexpected server-side code execution or unusual SharePoint worker process behavior after patching.
- Review SharePoint logs for anomalous deserialization or post-exploitation activity.
Detection
- Hunt for suspicious child processes spawned by SharePoint worker processes (w3wp.exe, spucworkerprocess.exe).
- Monitor for unusual outbound network connections from SharePoint servers.
- Alert on unexpected file writes or web shell creation in SharePoint directories.
- Correlate privileged SharePoint account activity with anomalous server-side execution events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044 | Vendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044 | Vendor Advisory |
Track CVE-2024-30044 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-30044), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.