Vulnerability record · CVE-2024-38024 · published 9 July 2024
CVE-2024-38024: Microsoft SharePoint Server deserialization remote code execution
Microsoft · Sharepoint Server
CVE-2024-38024 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It matters because a successful exploit gives full control over code execution in the SharePoint context, and the EPSS score places it in the top percentile of likely-exploited vulnerabilities.
Description
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh CVSS (7.2) remote code execution with a very high EPSS percentile, though exploitation requires privileged access and no KEV listing or public exploit is confirmed.
What it is
CVE-2024-38024 is a deserialization of untrusted data flaw (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It matters because a successful exploit gives full control over code execution in the SharePoint context, and the EPSS score places it in the top percentile of likely-exploited vulnerabilities.
Impact
An attacker who exploits this flaw can execute arbitrary code on the SharePoint server, gaining high confidentiality, integrity and availability impact. This can lead to full server compromise and lateral movement within the network.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N), but requires high privileges (PR:H), meaning an attacker must already hold an administrative or otherwise privileged SharePoint account. No public proof-of-concept or exploitation details are provided in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS shows a 30-day exploitation probability of 0.45219 (98.7th percentile), indicating a high likelihood of exploitation activity. The only references are Microsoft patch and vendor advisory links, with no public exploit code or in-the-wild reports cited.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory immediately.
- Restrict and audit privileged SharePoint accounts, enforcing least privilege and multi-factor authentication.
- Monitor SharePoint server logs for suspicious deserialization or unexpected process creation.
- Segment SharePoint servers from other critical systems to limit lateral movement if compromised.
- Review and harden SharePoint configuration, disabling unnecessary features and web parts.
Detection
- Monitor for unusual child processes spawned by SharePoint worker processes (w3wp.exe, spucworkerprocess.exe).
- Alert on deserialization-related .NET exceptions or suspicious serialized payloads in SharePoint logs.
- Track creation or modification of unexpected files in SharePoint web directories or temporary folders.
- Correlate privileged SharePoint account activity with outbound network connections or command execution.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38024 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38024 | PatchVendor Advisory |
Track CVE-2024-38024 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38024), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.