{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2024-30043/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:*:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2016:*:*:*:enterprise:*:*:*","cpe:2.3:a:microsoft:sharepoint_server:2019:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.5,"id":"CVE-2024-30043"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SharePoint Server (\u003c 16.0.17328.20292, 2016, 2019)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","xxe","sharepoint","cve-2024-30043"],"_cs_type":"threat","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eCVE-2024-30043 is an XML External Entity (XXE) injection vulnerability affecting Microsoft SharePoint Server. The vulnerability is caused by improper handling of URL parsing, which allows an attacker to manipulate XML entities processed by the server. By sending specially crafted HTTP requests to the target SharePoint instance, an unauthenticated attacker can force the server to parse malicious XML, resulting in the disclosure of local files or internal resources. A proof-of-concept (PoC) Python script has been published on the KitPloit platform, confirming the exploitability of the flaw on SharePoint Server 2019 versions including 16.0.10409.20027. Defenders should prioritize patching, as the availability of functional exploit code significantly increases the risk of exploitation in the wild.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an internet-facing Microsoft SharePoint Server instance.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request leveraging URL parsing confusion to embed an external DTD (Document Type Definition) reference.\u003c/li\u003e\n\u003cli\u003eAttacker sends the crafted POST request to the target SharePoint application endpoint.\u003c/li\u003e\n\u003cli\u003eThe SharePoint server processes the XML payload, triggering the XXE vulnerability during the parsing phase.\u003c/li\u003e\n\u003cli\u003eThe server attempts to resolve the external entity, allowing the attacker to access restricted files or internal network resources.\u003c/li\u003e\n\u003cli\u003eThe server returns the contents of the requested resource back to the attacker via the HTTP response.\u003c/li\u003e\n\u003cli\u003eAttacker successfully exfiltrates sensitive server-side data (e.g., configuration files or internal service responses).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-30043 allows unauthorized actors to read arbitrary files from the SharePoint server or reach internal services. This leads to the loss of confidentiality regarding server configuration, sensitive business data, and potentially internal network architecture information. The vulnerability affects SharePoint Server 2016 and 2019 versions prior to build 16.0.17328.20292.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all Microsoft SharePoint Server deployments to build 16.0.17328.20292 or later immediately.\u003c/li\u003e\n\u003cli\u003eInspect web access logs for anomalous POST requests containing XML-related keywords or unusual URL parsing patterns targeting SharePoint endpoints.\u003c/li\u003e\n\u003cli\u003eAudit internet-facing SharePoint instances to ensure they are not exposing sensitive backend XML processing interfaces.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-04T09:02:53Z","date_published":"2026-09-04T09:02:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-30043-xxe/","summary":"A publicly available exploit for CVE-2024-30043 allows unauthenticated remote attackers to perform XML External Entity (XXE) injection against Microsoft SharePoint Server via URL parsing confusion, potentially leading to sensitive data disclosure.","title":"Exploitation of CVE-2024-30043 XXE in Microsoft SharePoint Server","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2024-30043-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2024-30043","version":"https://jsonfeed.org/version/1.1"}