Imported from CISA KEV catalog — never analyzed by ThreatLevel. This CVE is part of the CISA Known Exploited Vulnerabilities catalog. Only data from CISA KEV and NVD is shown below; no AI analysis or priority classification has been computed.
Unclassified

CVE-2024-38094

Microsoft SharePoint Deserialization Vulnerability

Summary

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.

Classification

This CVE has no priority classification because it was imported directly from the CISA KEV catalog without running the AI analysis pipeline. CISA KEV listing implies active exploitation in the wild; treat with the urgency that implies.

Exploitation Details

Type
Is exploitable with default configuration?
?
Is authentication needed?
?
PoC / Exploit
No
Impact

Detection Resources
Manual Detection
0
Script Detection
0
Scanner Detection
0

Affected Software

Vendor:Microsoft
ProductAffected Versions
SharePointUnknown
Deployment:
|
Protocol:
|
Ports:
Enterprise UsageEstimated likelihood that this vendor/product is deployed in enterprise environments. AI-generated estimation based on market presence, product type and adoption signals — not exact data.
Very Low
Low
Medium
High
Very High
Vendor Size:
Vendor Notifications
Not available
Remediation
Workaround

Not available

Patch

Not available

Update

Not available

Threat Intelligence
EPSS Score64.3%

Probability of exploitation in the next 30 days

EPSS Percentile98%

Worse than 98% of all CVEs

Last updated: Loading...
CISAKEV
CISA KEV
Listed
Loading...
Active Exploitation
Active
cisa.gov
Threat Actors

No known threat actors

Detection Rules

No detection rules available

NVD Data

Published: Loading...Modified: Loading...

Description Summary

No description available

CVSS Base Score

7.2
High

CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Attack Vector (AV)
Physical
Local
Adjacent
Network
Attack Complexity (AC)
High
Low
Privileges Required (PR)
High
Low
None
User Interaction (UI)
Required
None
Scope (S)
Unchanged
Changed
Confidentiality (C)
None
Low
High
Integrity (I)
None
Low
High
Availability (A)
None
Low
High
CWE:CWE-502 Deserialization of Untrusted Data
||
Version From:
|
Version Upto:

Affected Software (CPE) (3)

  • cpe:2.3:a:microsoft:sharepoint_server:-:*:*:*:subscription:*:*:*
  • cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*
  • cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*

Sources

0

No sources

Priority History

No priority changes recorded