ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

CISA Adds Critical Microsoft SharePoint Vulnerability (CVE-2024-38094) to Known Exploited Vulnerabilities Catalog

Paul by Paul
October 23, 2024
in Exploits
Reading Time: 2 mins read
Microsoft Sharepoint vulnerability CVE-2024-38094 exposed
Share on FacebookShare on Twitter

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has escalated concerns over a significant Microsoft SharePoint vulnerability by adding it to its Known Exploited Vulnerabilities (KEV) catalog. The security flaw, identified as CVE-2024-38094, poses a serious risk to SharePoint Server installations and requires immediate attention from federal agencies and private organizations alike.

Understanding the Vulnerability

The vulnerability, which carries a CVSS v4 score of 7.2, primarily affects the SharePoint Server Search component through an input validation error. What makes this security flaw particularly concerning is that authenticated attackers with Site Owner permissions can exploit it to:

  • Inject arbitrary code into the system
  • Execute malicious code within the SharePoint Server context
  • Potentially gain unauthorized control over the server

Federal Mandate and Timeline

Under Binding Operational Directive (BOD) 22-01, CISA has established a strict timeline for addressing this vulnerability:

  • Federal Civilian Executive Branch (FCEB) agencies must implement fixes by November 12, 2024
  • The directive aims to reduce significant risks associated with known exploited vulnerabilities
  • Private organizations are strongly encouraged to follow similar remediation timelines

Technical Details

The vulnerability stems from improper input validation in the SharePoint Server Search component. Attackers can potentially exploit this flaw by:

  1. Sending specially crafted HTTP requests to vulnerable servers
  2. Leveraging Site Owner permissions to execute unauthorized code
  3. Compromising system integrity through code injection

Additional Security Developments

In related cybersecurity news, CISA has also added the ScienceLogic SL1 vulnerability to its KEV catalog. This separate security issue:

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

  • Affects a third-party component within ScienceLogic SL1
  • Has been patched in versions 12.1.3+, 12.2.3+, and 12.3+
  • Includes backward-compatible fixes for versions dating to 10.1.x

Recent Impact and Response

The significance of addressing these vulnerabilities is highlighted by a recent security incident at Rackspace, reported on September 24, 2024. The cloud hosting provider experienced a breach through their ScienceLogic EM7 monitoring tool, resulting in:

  • Exposure of low-sensitivity performance monitoring data
  • Compromise of customer usernames and account information
  • Access to encrypted internal credentials

Organizations are advised to review their SharePoint Server installations and apply necessary security updates promptly to prevent potential exploitation of these vulnerabilities.

Previous Post

Apple Patches Critical Security Flaw (CVE-2024-44133) in macOS Safari: HM Surf Vulnerability

Next Post

LinkedIn Hit with €310 Million GDPR Fine Over Data Privacy Violations

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
What is DoubleClickJacking?

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024

Vulnerability (CVE-2024-54143 ) Discovered in OpenWrt’s Firmware Upgrade System

December 13, 2024

Cybercriminals Unleash Advanced Phishing-as-a-Service Toolkit Targeting Microsoft 365 Users

November 29, 2024

Major Security Vulnerability Uncovered in qBittorrent Client

November 1, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.