Risks of Unpatched Sharepoint Servers

Explore top LinkedIn content from expert professionals.

Summary

Unpatched SharePoint servers are vulnerable to serious security risks, including unauthorized access, data theft, and persistent backdoors that can allow attackers to remain unnoticed even after updates. These vulnerabilities are often exploited by cybercriminals to gain control over sensitive business collaboration platforms, making prompt investigation and ongoing monitoring essential.

  • Investigate immediately: Run memory forensics and inspect directories for webshells or suspicious files to uncover any hidden threats before they cause more damage.
  • Rotate security keys: If compromise is detected, change cryptographic keys and review access tokens to cut off attackers’ persistent access.
  • Limit internet exposure: Restrict public access to on-premises SharePoint servers and monitor for abnormal activity to reduce the likelihood of future breaches.
Summarized by AI based on LinkedIn member posts
  • View profile for Austin Larsen

    Principal Threat Analyst @ Google Threat Intelligence Group

    16,095 followers

    ⚠️ Google Threat Intelligence Group is tracking active exploitation of a SharePoint Zero-Day vulnerability. Tonight, Microsoft released CVE-2025-53770 to track a critical, unpatched vulnerability in on-premise SharePoint servers that is being actively exploited. GTIG has observed threat actors using this flaw to install webshells and exfiltrate cryptographic MachineKey secrets from victim servers. The theft of the MachineKey is critical because it allows attackers persistent, unauthenticated access that can bypass future patching. Organizations with vulnerable, public-facing SharePoint instances must urgently investigate for compromise and be prepared to rotate these keys to fully remediate the threat. There is no patch available yet. Here are the immediate actions for any organization running on-premise SharePoint: 🛡️ 1. Apply Mitigations: Microsoft's primary mitigation is to configure the AMSI integration with SharePoint and ensure Microsoft Defender AV is active. If you cannot, consider disconnecting SharePoint from the internet until a patch is available. 🔎 2. Hunt for Compromise: Actively search for webshells in SharePoint directories. The presence of a webshell is a definitive sign of compromise. 🔑 3. Rotate Keys if Compromised: If you find evidence of compromise, you must isolate the server and rotate the SharePoint MachineKey. Simply removing the webshell is not enough. The attacker already has the keys, and rotating them is the only way to invalidate their access. #SharePoint #CyberSecurity #ThreatIntel #InfoSec #0day #CVE #GTIG

  • View profile for Esesve Digumarthi

    Founder of EnH group of Organizations

    8,251 followers

    Patching won’t save you this time. And Microsoft just said it out loud. In response to the actively exploited SharePoint zero-day, Microsoft and CISA have rushed out emergency patches and technical guidance. But here’s the critical line most executives are missing: “𝐏𝐚𝐭𝐜𝐡𝐢𝐧𝐠 𝐚𝐥𝐨𝐧𝐞 𝐢𝐬 𝐧𝐨𝐭 𝐬𝐮𝐟𝐟𝐢𝐜𝐢𝐞𝐧𝐭. 𝐁𝐚𝐜𝐤𝐝𝐨𝐨𝐫𝐬 𝐦𝐚𝐲 𝐩𝐞𝐫𝐬𝐢𝐬𝐭.” That’s not a casual warning. It’s a red flag to every SOC, IR team, and enterprise CISO that remediation is no longer just about software updates—it’s about 𝐟𝐮𝐥𝐥 𝐟𝐨𝐫𝐞𝐧𝐬𝐢𝐜 𝐭𝐫𝐢𝐚𝐠𝐞. Because this exploit didn’t just allow remote code execution. It enabled 𝐬𝐭𝐞𝐚𝐥𝐭𝐡𝐲, 𝐩𝐞𝐫𝐬𝐢𝐬𝐭𝐞𝐧𝐭 𝐛𝐚𝐜𝐤𝐝𝐨𝐨𝐫 𝐢𝐧𝐬𝐭𝐚𝐥𝐥𝐚𝐭𝐢𝐨𝐧—the kind that survives restarts, evades basic EDR, and blends in with legitimate SharePoint services. Once inside, attackers likely leveraged built-in tools, hijacked tokens, and pivoted laterally—leaving minimal footprints. So if your mitigation plan ends at CVE patching, you’re already behind. What you need now is: — Deep process memory inspection — Audit of service principal tokens and app identities — Rollback analysis of recent config drifts — Anomaly detection in service account behaviors — Hard resets of cryptographic material, if exposed This is a 𝐩𝐨𝐬𝐭-𝐜𝐨𝐦𝐩𝐫𝐨𝐦𝐢𝐬𝐞 𝐬𝐜𝐞𝐧𝐚𝐫𝐢𝐨, not a containment issue. CISOs must shift from “are we patched?” to “have we been lived in?” Because advanced actors don’t breach to vandalize—they breach to linger. This breach has changed the SharePoint threat model permanently. Time to treat collaboration platforms as Tier-0 assets—because that’s exactly how the attackers see them. #CRM #CyberSecurity #SalesforceSecurity #SaaSHardening #HubSpot #AccessControl #ZeroTrust #DataBreach #RevenueOps #SaaSSecurity #InfoSec #CISO

  • View profile for Robert Wortmann

    Principal Security Strategist @TrendAI

    3,054 followers

    🚨 Assume Breach. Even If You See Nothing. 🚨 A wave of attacks is hitting Microsoft SharePoint, exploiting CVE-2025-53770. This isn’t just another vulnerability, it’s a critical, unauthenticated remote code execution (RCE) flaw under active, surgical exploitation. Patches dropped on July 20 and July 21 for SharePoint Subscription Edition and 2019 and SharePoint 2016. CISA added it to the KEV catalog, and a good amount of servers are already compromised. Your SIEM or XDR might be quiet, but that doesn’t mean you’re safe. The vulnerability ties back to the “ToolShell” exploit chain (CVE-2025-49704 and CVE-2025-49706), showcased at Pwn2Own Berlin in May 2025. Huge props to Viettel Cyber Security for their responsible disclosure through Trend Zero Day Initiative. At Trend Micro, our TippingPoint protections, rolled out in May for related flaws, have been shielding against CVE-2025-53770 attacks using the power of the bug bounty program integrated in Tipping Point threat intelligence. But protection is only step one. Here’s the hard truth: Threat actors are already inside networks, using this as a foothold to steal credentials, plant backdoors, and move laterally. These attacks are stealthy, blending seamlessly into normal SharePoint activity. You usually won’t spot them in standard logs, and ransomware isn’t the immediate goal—persistence is. If you’re not hunting for trouble, you’re already behind. This isn’t a “patch and move on” moment. It’s a “drop everything and investigate” moment. Run memory forensics. Hunt for post-exploitation signs like spinstall0.aspx in your Web Server Extensions folder. Scrutinize SharePoint config files, check for webshells, and dig into proxy logs for suspicious POST requests to /_layouts/15/ToolPane.aspx. Act now, or you’re giving attackers free rein. Trend Micro has detailed technical guidance and IOCs out, and we’re working closely with partners to track these exploitation patterns. If you need help gauging your exposure or want to strengthen detection, prevention, or response, let’s connect.

  • View profile for Flavio Queiroz, MSc, CISSP, CISM, CRISC, CCISO

    Cybersecurity Leader | Information Security | GRC | Security Operations | Mentor | GSOC, GCIH, GDSA, GISP, GPEN, GRTP, GCPN, GDAT, GCISP, GCTIA, CTIA, eCMAP, eCTHP, CTMP

    31,447 followers

    THREAT CAMPAIGN: STORM-2603 EXPLOITS SHAREPOINT VULNERABILITIES TO DEPLOY WARLOCK RANSOMWARE ON UNPATCHED SYSTEMS ℹ️ Microsoft has observed an increase in exploitation of on-premises SharePoint vulnerabilities, specifically CVE-2023-29357 and CVE-2023-24955. These flaws allow unauthenticated attackers to gain privileges and execute code remotely, making them attractive targets for cybercriminals. ℹ️ The main actor exploiting these vulnerabilities is identified as Storm-2603, a China-based threat group. Their operations are focused on espionage, targeting government and private sector organizations. They exploit SharePoint as an initial access vector to establish persistence and exfiltrate data. ℹ️ The attackers combine a spoofed JWT token exploit (CVE-2023-29357) with an arbitrary file upload (CVE-2023-24955). Once inside, they deploy custom web shells, establish persistence via scheduled tasks, and use tools like PowerShell and Mimikatz to escalate privileges and move laterally. ℹ️ Microsoft strongly urges all organizations to apply patches for vulnerable SharePoint versions, limit internet exposure of on-prem services, monitor abnormal access patterns, and follow secure identity and access practices. #threathunting #threatdetection #threatanalysis #threatintelligence #cyberthreatintelligence #cyberintelligence #cybersecurity #cyberprotection #cyberdefense

  • View profile for Joseph Emerick

    Cyber & Information Security Professional | Ambassador | Mentor | CISSP-ISSMP, CCSP, C|CISO, C|TIA, C|HFI, C|EH, CCSKv5, CNVP, CSCP, CCAP, CSIS, CIOS, CSSS, CLNP

    6,292 followers

    🚨 85 orgs breached. No patch. No warnings. Just silence. Microsoft SharePoint is under active attack—CVE-2025-53770 enables unauthenticated remote code execution using stolen MachineKeys and weaponized __VIEWSTATE payloads. ToolShell chaining makes this the most dangerous SharePoint exploit since CVE-2019-0604. ☠️ Governments and global enterprises already compromised. 👀 Your server could be next—and traditional MFA won’t help. 🔎 Full threat breakdown, mitigation roadmap, IOCs, and threat hunting queries inside. This is the kind of vulnerability that reshapes policy. Read it before the threat actors do. #CyberSecurity #SharePoint #ZeroDay #RCE #ThreatIntelligence #Infosec #Microsoft #vulnerability #BlueTeam #RedTeam 👇Click below to read full article 👇

  • 🚨This week’s CCTR.30.JUL.25 is an emergency notification on the active exploitation of a SharePoint zero-day. ☕️ 📌If you are running on-prem SharePoint exposed to the internet, now is the time to act! No patch is available yet. 📌A critical remote code execution vulnerability (CVE-2025-53770), dubbed ToolShell, is being actively exploited in the wild. ⚠️It affects on-premises Microsoft SharePoint Server and allows unauthenticated attackers to gain access to your IT environment over the internet. ⚠️SharePoint is often tightly integrated with Outlook, Teams and OneDrive, increasing the risk of lateral movement and data theft. 📌Confirmed attacks also bypass identity protections like MFA, SSO and enabling, 🔺Full access to SharePoint content, configurations and system files 🔺Lateral movement across the Windows domain 🔺Theft of cryptographic keys enabling long term user/service impersonation 🔺Persistence via backdoors or modified components that survive reboots 𝐀𝐜𝐭 𝐧𝐨𝐰! ✅ Do not wait for a patch, assess for compromise immediately ✅ Hunt for signs of intrusion ✅ If exposed, rotate secrets and cryptographic keys. Patching alone won’t revoke stolen tokens ✅ Engage expert incident response support if needed ✅ Monitor Microsoft advisories closely for updates here https://lnkd.in/gyi-rrns 🚨This is a high-impact, targeted zero-day. Treat it as an emergency. Read on Eye Security https://lnkd.in/grg-Bcr5 Australian Signals Directorate https://lnkd.in/g7kt-Urg

  • View profile for Lou Rabon

    Founder and CEO @ Cyber Defense Group | CISSP, CIPP/US

    3,788 followers

    The new Microsoft Sharepoint vulnerability has a CVSS of 9.8 out of 10. Sharepoint Online is not affected. Everyone is going to be talking about this, so in order to not rehash what 1M AI chatbots might write about it, here's the TL;DR: -If you have on-prem Sharepoint that had open exposure to the internet, you should consider yourself compromised and start hunting for IOCs immediately, even if you patched it and took it offline quickly (see https://lnkd.in/gi8NsDB9). -Any networks that the external-facing sharepoint server was connected to should be considered compromised as well - re-examine your network segmentation strategy (DMZ ftw). -Rotate secrets and harden this server - consider additional protection including NGFW, WAF, etc. -Ensure you have proper monitoring with IOC alerts before attempting to put this back online. Better yet, put it behind a VPN or authentication portal before allowing access.

  • View profile for María Luisa Redondo Velázquez

    Driving Business & Digital Transformation | Enterprise Technology Strategy | Cloud, Cybersecurity, AI & Innovation | Business Strategy | Cyber Defense | Top 100 Chief Innovation & Information Officer | Board Advisor

    10,205 followers

    🔴 Breaking Cyber Alert: SharePoint Zero-Day Under Active Exploitation! ⚠️ Google’s Threat Intelligence Group is tracking active attacks exploiting a new SharePoint Server vulnerability — CVE-2025-53770. 📢 Microsoft has officially released the advisory tonight. This is not just another CVE — this one scores 9.8 Critical (CVSS) and allows unauthenticated remote code execution via deserialization of untrusted data. 🧨 What’s happening? Attackers are targeting on-prem SharePoint servers using malicious .aspx payloads (e.g., spinstall0.aspx) to execute code without any credentials. Once exploited, they gain full control, upload backdoors, and move laterally across your network. 🛡️ No patch yet — but Microsoft recommends: ✔️ Enabling AMSI protection for SharePoint ✔️ Using Microsoft Defender for Endpoint/AV ✔️ Isolating vulnerable servers from the internet ✔️ Hunting for indicators like rogue .aspx uploads or ToolPane abuse 🕵️♂️ If you see ToolShell patterns, HijackSharePointServer.A, or SuspSignoutReq.A alerts — don’t ignore them. 📌 Too Long, Didn’t Read: • CVE-2025-53770 • Affects: SharePoint Server (on-prem) • CVSS: 9.8 (Critical) • Exploited: In the wild — now • Patch: Not yet released • Action: Apply mitigations immediately 💬 Are your systems at risk? How is your team responding to this threat? Let’s discuss zero-day response strategies. #SharePoint #CyberSecurity #ZeroDay #CVE2025_53770 #threatintel #Microsoft #InfoSec #CyberAttack #PatchNow #BlueTeam #IncidentResponse #VulnerabilityManagement #SOC #BlueTeamOps #Deserialization #RCE #Infosec #Informationsecurity

  • View profile for Syed Amoz

    Co-founder Genesis Platform | Cybersecurity | Cyber Risk Quantification

    5,107 followers

    ⚠️Globally, about 9–10k on-prem SharePoint servers are still exposed to the internet. Even if your infrastructure is 100% cloud, odds are a significant portion of your vendors, SaaS providers, or regional partners still operate on-prem SharePoint. Still unpatched. Potential Third-Party Attack Path: 🔻 Initial access - Exploit CVE-2025-49704 / 49706 / 53770 / 53771 on an exposed SharePoint server to achieve RCE. 🔻Credential/key theft -Pull machine keys/service creds to enable token forgery and broader access. 🔻Persistence - Web shells (ASPX) dropped to survive patching. CISA Privilege escalation - Pivot inside vendor environment (AD, DBs, internal apps). 🔻Lateral movement - Reach integrated systems and hosted client data. 🔻Impact -Ransomware deployment, data exfiltration, or tampering with connected workloads. Downstream risk to clients (you): 🔺Data exposure if the vendor processes or stores your data. 🔺Credential/secret reuse into your systems (integration keys, API creds, SSO tokens). 🔺Supply-chain injection (malicious updates/content delivered via trusted vendor channels). What you can control (modern TPRM): ➡️ Asset Ownership First - Know exactly which vendors run SharePoint on-prem and where those assets live. ➡️Real-Time Threat Correlation - Tie active CVEs/IOCs directly to known vendor assets; watch for exploit spikes. ➡️Business-Context Mapping - Rank vendors by data sensitivity and operational dependency so you can isolate or throttle access when risk rises. (This is the operational lesson from federal impacts.) ▶️ IoCs & Detection: (According to CISA) 🔺Monitor POST requests to /_layouts/15/ToolPane.aspx?DisplayMode=Edit. 🔺HTTP referrer signature: /_layouts/SignOut.aspx. 🔺Watch for scans involving IPs: 107.191.58[.]76, 104.238.159[.]149, 96.9.125[.]147. 🔺Inspect applicationHost.config and web.config for malicious module entries post-iisreset. Release Date: August 06, 2025 Full List of IoCs: https://lnkd.in/dda-s42j #tprm #cybersecurity #thirdpartyriskmanagement #sharepoint

Explore categories