Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation — SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including log analysis, endpoint investigation, and incident response procedures. | Kitploit
Tools/GitHubGitHub/deividasterechovas/soc227-microsoft-sharepoint-server-elevation-of-privilege-possible-cve-2023-29357-exploitation
Privilege EscalationVulnerability AnalysisWeb SecurityLearning & EducationIncident ResponseLog Analysis
GitHubdeividasterechovas/soc227-microsoft-sharepoint-server-elevation-of-privilege-possible-cve-2023-29357-exploitation

SOC227-Microsoft-SharePoint-Server-Elevation-of-Privilege-Possible-CVE-2023-29357-Exploitation

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

SOC case analysis walkthrough demonstrating detection and response to CVE-2023-29357 privilege escalation in Microsoft SharePoint Server, including log analysis, endpoint investigation, and incident response procedures.

View Repository
141 year agoNot yet reviewed

SOC227 - Microsoft SharePoint Server Elevation of Privilege (CVE-2023-29357 Exploitation)

CVE-2023-29357 is a critical privilege escalation vulnerability that, when combined with other vulnerabilities, could potentially lead to remote code execution. The CVSS score for this vulnerability is 9.8 (Critical).


Event Information

  • EventID: 189

  • Event Time: Oct 06, 2023, 08:05 PM

  • Rule: SOC227 - Microsoft SharePoint Server Elevation of Privilege - Possible CVE-2023-29357 Exploitation

  • Level: Security Analyst

  • Hostname: MS-SharePointServer

  • Destination IP Address: 172.16.17.233

  • Source IP Address: 39.91.166.222

  • HTTP Request Method: GET

  • Requested URL: /api/web/siteusers

  • User-Agent: python-requests/2.28.1

  • Alert Trigger Reason: This activity may indicate an attempt to exploit CVE-2023-29357, potentially leading to unauthorized access and privilege escalation within the SharePoint server.


Investigation Process

We began by focusing on the following key areas:

  1. Log Management
  2. Endpoint Security

Log Management

The source IP address that triggered the alert was flagged by our firewall 3 times. Upon further inspection of the logs:

  • Event 1: The GET request returned a HTTP 404 status (Not Found).
  • Event 2 & 3: Both returned HTTP 200 statuses, indicating that the attacker successfully received the requested response.

Endpoint Security Investigation

We connected to the MS-SharePointServer device and found no relevant information in the browser or terminal history. We then analyzed the system processes and identified several concerning ones.


Process Analysis

1. svchost.exe

  • Command: C:\Windows\System32\svchost.exe -k termsvcs -s TermService
  • Explanation:
    • svchost.exe is the Service Host Process, which runs Windows services.
    • -k termsvcs specifies that this instance is hosting the Terminal Services group.
    • -s TermService starts the Remote Desktop Services.

2. MpCmdRun.exe

  • Command: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23080.2006-0\MpCmdRun.exe" SignaturesUpdateService -ScheduleJob -UnmanagedUpdate
  • Explanation:
    • MpCmdRun.exe is the Microsoft Defender Command-Line Utility used for Defender-related tasks.
    • SignaturesUpdateService performs a virus definition update.
    • -ScheduleJob schedules the update as a background task.
    • -UnmanagedUpdate forces the update even if the system isn't managed by Group Policy or Microsoft Endpoint Manager.

3. svchost.exe

  • Command: C:\Windows\system32\svchost.exe -k DcomLaunch -p
  • Explanation:
    • svchost.exe is hosting the DcomLaunch service group responsible for DCOM and COM+ services.
    • -p runs svchost.exe as a protected process to enhance security.

Conclusion and Response

After reviewing the collected data, we followed the appropriate playbook steps and confirmed the traffic as malicious.

  • Attack Type: Privilege escalation.
  • Planned Test: No penetration testing was confirmed via email during the event timeframe.
  • Action Taken: The affected device was quarantined. Further escalation to T2 is required for additional investigation and response.

Next Steps

  • Escalation: The issue was escalated to the T2 team for further investigation and remediation.
  • Continuous Monitoring: We will continue to monitor for further exploitation attempts and ensure the integrity of the SharePoint server.

Result:

Note: This post is part of a SOC case analysis demonstrating the detection and response to a privilege escalation vulnerability (CVE-2023-29357) within a SharePoint environment.

Playbook Procedure:

Download Tool