Back to Hub

Microsoft SharePoint Zero-Day Exploited in Global Attacks, Emergency Patch Released

Imagen generada por IA para: Ataques globales explotan zero-day en SharePoint; Microsoft publica parche de emergencia

Microsoft is scrambling to contain a widespread cybersecurity crisis as attackers exploit a critical zero-day vulnerability in SharePoint Server before the company could issue a fix. The vulnerability, now patched in emergency out-of-band updates, affects SharePoint Enterprise Server 2016 and 2019, putting thousands of government agencies and corporations at risk.

The flaw (CVE-2025-XXXXX) resides in SharePoint's ToolShell component, allowing authenticated attackers to execute arbitrary code remotely. Security researchers have observed active exploitation since at least early July 2025, with attack volumes spiking dramatically last week. Microsoft's Security Response Center described the situation as 'an urgent and active threat' requiring immediate action.

According to telemetry data, approximately 10,000 organizations worldwide may be vulnerable, particularly those using SharePoint for document management and collaboration. The attacks appear highly targeted, focusing on government entities in North America and Europe, along with enterprises in the financial and healthcare sectors.

Technical analysis reveals the exploit chain involves:

  1. Authentication bypass techniques to gain initial access
  2. Weaponization of ToolShell features for privilege escalation
  3. Deployment of web shells for persistent access
  4. Lateral movement through connected systems

Microsoft's emergency patch completely disables the vulnerable ToolShell functionality while maintaining backward compatibility. The company has also released detection scripts to help identify potential compromises.

Cybersecurity teams should prioritize:

  • Immediate application of July 2025 SharePoint security updates
  • Inspection of SharePoint servers for suspicious .aspx files
  • Review of authentication logs for unusual patterns
  • Network segmentation of SharePoint environments

The incident highlights growing concerns about enterprise collaboration platforms becoming prime targets for advanced threat actors. With SharePoint's deep integration into organizational workflows, successful compromises can provide attackers with extensive access to sensitive documents and communication channels.

Original sources

NewsSearcher

This article was generated by our NewsSearcher AI system, analyzing information from multiple reliable sources.

Microsoft issues emergency SharePoint patches for ToolShell

Windows Central
View source

Microsoft releases urgent fix for SharePoint zero-day vulnerability

Mashable India
View source

Microsoft Sharepoint server vulnerability puts an estimated 10,000 organizations at risk

Engadget
View source

Microsoft fixes Sharepoint vulnerability after global cyberattacks

CP24 Toronto
View source

Microsoft Sharepoint: Sicherheitslücke betrifft Zehntausende Kunden

Süddeutsche Zeitung
View source

Microsoft releases urgent SharePoint security flaw patches - here's what you need to know, and how to update

TechRadar
View source

What to know about a vulnerability being exploited on Microsoft SharePoint servers

Toronto Star
View source

Falha no SharePoint: entenda o ataque hacker que expôs servidores da Microsoft

InfoMoney
View source

⚠️ Sources used as reference. CSRaid is not responsible for external site content.

This article was written with AI assistance and reviewed by our editorial team.

Comentarios 0

¡Únete a la conversación!

Sé el primero en compartir tu opinión sobre este artículo.