Stop the Presses! Microsoft’s June Patch Tuesday Drops a SharePoint Zero-Day Bomb
Microsoft just rolled out its June 2024 Patch Tuesday, and it’s not just a routine update – it includes fixes for a critical zero-day vulnerability in SharePoint and a nasty RCE in Message Queuing. This isn’t one you want to snooze on; these bugs could give attackers a direct path into your network.
Let’s get technical. The big shocker is CVE-2024-30080, a Remote Code Execution vulnerability in Microsoft SharePoint Server that’s already being actively exploited in the wild[1]. This zero-day affects SharePoint Server Subscription Edition, 2019, and 2016, and it’s the kind of flaw that keeps security teams up at night. Attackers can leverage it to execute arbitrary code with elevated privileges on vulnerable SharePoint servers. Then there’s CVE-2024-30089, a critical Remote Code Execution vulnerability in Microsoft Message Queuing (MSMQ) with a CVSS score of 9.8[2]. While not yet exploited in the wild, its severity means it’s only a matter of time before threat actors weaponize it. This MSMQ flaw impacts numerous Windows Server and client versions, allowing unauthenticated remote code execution without user interaction.
So what? If you run SharePoint or rely on MSMQ, consider this your five-alarm fire drill. A zero-day in SharePoint means active exploitation is already happening, potentially leading to full system compromise, data theft, or worse. The MSMQ RCE



