Vulnerability record · CVE-2024-38094 · published 9 July 2024
CVE-2024-38094: Microsoft SharePoint deserialization flaw enables remote code execution
Microsoft · Sharepoint Server
CVE-2024-38094 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It carries a CVSS 3.1 score of 7.2 (HIGH) and has been added to CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation. The record gives only a one-line description, so the specific vulnerable component and affected versions are not stated.
Description
Microsoft SharePoint Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use and a high EPSS score, so active exploitation is expected despite the high-privilege requirement.
What it is
CVE-2024-38094 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server that allows remote code execution. It carries a CVSS 3.1 score of 7.2 (HIGH) and has been added to CISA's Known Exploited Vulnerabilities catalog, indicating real-world exploitation. The record gives only a one-line description, so the specific vulnerable component and affected versions are not stated.
Impact
A successful attacker can execute arbitrary code on the SharePoint server, gaining the ability to run commands and potentially take over the host. CISA notes known ransomware campaign use, so impact can extend to data encryption and disruption.
Attack surface
The CVSS vector is network-reachable (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N), but requires high privileges (PR:H), meaning an attacker needs an authenticated account with elevated rights. No details on the exact endpoint or entry point are provided in the record.
Exploitation
CISA added this to the KEV catalog on 2024-10-22 with a due date of 2024-11-12 and flags known ransomware campaign use; EPSS gives a 30-day probability of 0.50892 (98.9th percentile). The references include only vendor patch advisories and the CISA KEV entry, with no public exploit write-up listed.
What to do
- Apply the Microsoft SharePoint security update referenced in the MSRC advisory for CVE-2024-38094 immediately.
- If patching cannot be completed, follow CISA's required action to apply vendor mitigations or discontinue use of the product.
- Restrict and audit high-privilege SharePoint accounts, since exploitation requires PR:H.
- Monitor for and limit exposure of SharePoint servers to untrusted networks where feasible.
- Review backup and recovery readiness given the known ransomware campaign use.
Detection
- Hunt for unexpected w3wp.exe or SharePoint worker process spawning of cmd.exe, powershell.exe, or other child processes.
- Monitor SharePoint server logs for anomalous deserialization or post-authentication requests from high-privilege accounts.
- Alert on indicators of ransomware activity on SharePoint hosts, such as mass file encryption or shadow copy deletion.
- Correlate SharePoint application events with network connections to unusual external hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-38094 to the Known Exploited Vulnerabilities catalog on 22 October 2024 as "Microsoft SharePoint Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 12 November 2024.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38094 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38094 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38094 | US Government Resource |
Track CVE-2024-38094 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-38094), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.