
SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including log analysis, endpoint investigation, and incident response procedures.
CVE-2023-29357 is a critical privilege escalation vulnerability that, when combined with other vulnerabilities, could potentially lead to remote code execution. The CVSS score for this vulnerability is 9.8 (Critical).
EventID: 189
Event Time: Oct 06, 2023, 08:05 PM
Rule: SOC227 - Microsoft SharePoint Server Elevation of Privilege - Possible CVE-2023-29357 Exploitation
Level: Security Analyst
Hostname: MS-SharePointServer
Destination IP Address: 172.16.17.233
Source IP Address: 39.91.166.222
HTTP Request Method: GET
Requested URL: /api/web/siteusers
User-Agent: python-requests/2.28.1
Alert Trigger Reason: This activity may indicate an attempt to exploit CVE-2023-29357, potentially leading to unauthorized access and privilege escalation within the SharePoint server.
We began by focusing on the following key areas:
The source IP address that triggered the alert was flagged by our firewall 3 times. Upon further inspection of the logs:
We connected to the MS-SharePointServer device and found no relevant information in the browser or terminal history. We then analyzed the system processes and identified several concerning ones.
C:\Windows\System32\svchost.exe -k termsvcs -s TermService"C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe" SignaturesUpdateService -ScheduleJob -UnmanagedUpdateC:\Windows\system32\svchost.exe -k DcomLaunch -pAfter reviewing the collected data, we followed the appropriate playbook steps and confirmed the traffic as malicious.
Note: This post is part of a SOC case analysis demonstrating the detection and response to a privilege escalation vulnerability (CVE-2023-29357) within a SharePoint environment.
