DETECTION OVERVIEW
Risk Factors
An authenticated attacker with the ability to upload files to a personal or shared folder on a SharePoint server could upload a web shell and directly run malicious code on the SharePoint server. Running web shells or other code is dependent on which SharePoint mitigations are configured, such as support for running code-blocks.
Category

Microsoft SharePoint has a vulnerability in how it processes incoming HTTP requests without validating URL parameters. An attacker could create an HTTP request with a specially designed URI for a file on a SharePoint server, resulting in remote code execution (RCE).
Install patches for relevant versions
Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.
ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response
Visit this resource for more information.
This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.
Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.
Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.
