Microsoft has released emergency out-of-band patches to fix two high-severity remote code execution (RCE) vulnerabilities in SharePoint Server, after both flaws were discovered to be actively exploited in the wild.
The vulnerabilities – CVE-2023-29357 and CVE-2023-24955 enable attackers to bypass authentication and gain elevated privileges on vulnerable on-premises Microsoft SharePoint servers. The implications are far-reaching, as SharePoint serves as a central hub for file sharing, collaboration, and data storage across government agencies, educational institutions, healthcare providers, and large enterprises.
Microsoft’s security bulletin classified the flaws as critical, urging customers to apply updates immediately. But experts say patching alone may not be enough to mitigate the full extent of the threat.
In a statement to the press, Michael Sikorski, CTO and Head of Threat Intelligence for Unit 42 at Palo Alto Networks, revealed the scale and sophistication of the campaign now underway:
“Unit 42 is tracking a high-impact, ongoing threat campaign targeting on-premises Microsoft SharePoint servers. While cloud environments remain unaffected, on-prem SharePoint deployments, particularly within government, schools, healthcare, including hospitals, and large enterprise companies, are at immediate risk.”
Sikorski warned that attackers are successfully bypassing identity protections such as multi-factor authentication (MFA) and single sign-on (SSO), and are moving laterally across networks to exfiltrate sensitive data, steal cryptographic keys, and establish persistent backdoors.
“If you have SharePoint on-prem exposed to the internet, you should assume that you have been compromised at this point. Patching alone is insufficient to fully evict the threat.”
According to Microsoft, the attackers are using a previously disclosed authentication bypass (CVE-2023-29357) to gain administrator privileges, which is then chained with an RCE vulnerability (CVE-2023-24955) to execute arbitrary code remotely. This chained exploit was demonstrated by StarLabs SG at Pwn2Own Vancouver 2023, and now appears to be deployed in real-world attacks.
Sikorski emphasised the systemic risk posed by SharePoint’s deep integration across Microsoft services, including Office, Teams, OneDrive and Outlook, making a single breach capable of triggering a widespread compromise.
“A compromise doesn’t stay contained – it opens the door to the entire network,” he said. “This is a high-severity, high-urgency threat. We are urging organisations who are running on-prem SharePoint to take action immediately.”
While Microsoft has released patches, experts warn that immediate response measures are still necessary:
- Disconnect vulnerable SharePoint servers from the internet.
- Apply all available Microsoft patches immediately.
- Rotate all cryptographic keys and certificates.
- Engage with professional incident response teams to assess scope of compromise.
“An immediate, band-aid fix would be to unplug your Microsoft SharePoint from the internet until a patch is available. A false sense of security could result in prolonged exposure and widespread compromise,” Sikorski warned.
Microsoft is continuing to coordinate with cybersecurity partners, including Palo Alto Networks and others, to monitor the campaign and issue additional protections.
For organisations reliant on SharePoint, especially those in regulated industries such as healthcare and public services, this incident is a reminder that default on-premises deployments are no longer a safe option without constant patching and layered defences.

