Serious Security Problems With Microsoft’s SharePoint Servers
Microsoft have disclosed a critical security problem has with its SharePoint servers, which has been weaponised as part of a large-scale exploitation campaign. Chinese hackers have penetrated Microsoft's SharePoint document software servers and targeted the data of the businesses using it.
China's state-backed Linen Typhoon and Violet Typhoon hacking groups, as well as Chinese-based Storm-2603, are reported to have exploited vulnerabilities in on-premises SharePoint servers, the kind used by many corporate users, but not in its cloud-based service.
Right now, more than 85 SharePoint servers globally have been identified as compromised with the malicious web shell and these hacked servers belong to 29 organisations, including multinational firms and government entities.
In confirmation, researchers at Check Point have observed exploitation attempts targeting an unnamed major Western government, with the activity intensifying on July 18 and 19, spanning government, telecommunications, and software sectors in North America and Western Europe.
Microsoft says it is aware that an exploit for CVE-2025-53770 exists and it has begun working on the problem and is preparing and fully testing a comprehensive update to address this vulnerability.
The zero-day flaw identified as CVE-2025-53770 (CVSS score: 9.8), has been described as a variant of CVE-2025-49706 (CVSS score: 6.3), a spoofing bug in Microsoft SharePoint Server that was worked on by Microsoft as part of its July 2025 Patch Tuesday updates.
Microsoft have credited Viettel Security for discovering and reporting the flaw through Trend Micro's Zero Day Initiative (ZDI).
Currently without an official patch, Microsoft is urging customers to configure Antimalware Scan Interface (AMSI) integration in SharePoint and deploy Defender AV on all SharePoint servers. It should be noted that AMSI integration is enabled by default in the September 2023 security update for SharePoint Server 2016/2019 and the Version 23H2 feature update for SharePoint Server Subscription Edition.
For those who cannot enable AMSI, it's advised that the SharePoint Server is disconnected from the Internet until a security update is available. Users are recommended to Use Defender for Endpoint to detect and block potential hacking activity.
Microsoft | Microsoft | Microsoft | Microsoft | BBC | Hacker News | Dark Reading | Reddit | TechTarget
Image: Ideogram
You Might Also Read:
MS Windows Zero Day Vulnerability Widely Exploited:
If you like this website and use the comprehensive 8,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.
- Individual £5 per month or £50 per year. Sign Up
- Multi-User, Corporate & Library Accounts Available on Request
- Inquiries: Contact Cyber Security Intelligence
Cyber Security Intelligence: Captured Organised & Accessible