Stopping Active Exploitation of On-Premises SharePoint Vulnerabilities

Microsoft Warns of Active Exploitation of On-Premises SharePoint Vulnerabilities

On July 19, 2025, the Microsoft Security Response Center (MSRC) issued a critical security advisory about ongoing attacks targeting on-premises SharePoint servers. These attacks exploit two newly disclosed vulnerabilities: CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution flaw. Importantly, these vulnerabilities do not impact SharePoint Online in Microsoft 365 — only on-premises installations are at risk.

Microsoft has released comprehensive security updates for all supported versions of SharePoint Server, including Subscription Edition, 2019, and 2016. These updates not only address CVE-2025-49706 and CVE-2025-49704, but also newly identified linked vulnerabilities — CVE-2025-53770 and CVE-2025-53771 — which are connected to previously disclosed issues. Microsoft urges all customers to install these patches immediately to mitigate risk.

The advisory notes that Microsoft has observed active exploitation of these vulnerabilities by Chinese nation-state actors. Specifically, threat groups Linen Typhoon and Violet Typhoon, as well as a third actor known as Storm-2603, have been targeting internet-exposed SharePoint servers. Microsoft warns that other groups may soon adopt the same techniques, given the widespread and rapid exploitation already underway.

To strengthen defenses, Microsoft strongly recommends that customers maintain up-to-date, supported versions of SharePoint with the latest security patches. Additional mitigation steps include enabling the Antimalware Scan Interface (AMSI) with Full Mode, using Microsoft Defender Antivirus or equivalent solutions, rotating ASP.NET machine keys, restarting Internet Information Services (IIS), and deploying Microsoft Defender for Endpoint.

The company emphasizes that the vulnerabilities are being used in active campaigns and that threat actors are employing sophisticated follow-on tactics, techniques, and procedures (TTPs) after gaining access. Investigations are ongoing, and Microsoft pledges to continue updating its blog with new information as it emerges.

Organizations using on-premises SharePoint are urged to act quickly to protect their environments. Applying the latest patches and following Microsoft’s mitigation guidance can help reduce exposure to these serious threats.

Related Posts

  • August 18, 2025
  • 81 views
US-India Trade Talks Postponed Amid Tariff Deadline Concerns

A planned visit by U.S. trade negotiators to New Delhi, scheduled from August 25–29, has been canceled, according to reports by NDTV Profit. The discussions were expected to advance talks…

  • August 18, 2025
  • 84 views
Air Canada Strike Grounds Thousands of Summer Travelers

Air Canada’s ongoing dispute with its unionized flight attendants has led to widespread flight cancellations, leaving thousands of passengers stranded and scrambling to change plans during peak summer travel. One…

Leave a Reply

Your email address will not be published. Required fields are marked *

Viral News

Bold $2 Million Jewelry Heist Rocks Seattle

  • 78 views
Bold $2 Million Jewelry Heist Rocks Seattle

Flash Flood Tragedy in Kishtwar: Cloudburst Strikes Pilgrimage Route

  • 84 views
Flash Flood Tragedy in Kishtwar: Cloudburst Strikes Pilgrimage Route

Maruti Suzuki Dzire Tops July 2025: India’s Best‑Selling Car

  • 452 views
Maruti Suzuki Dzire Tops July 2025: India’s Best‑Selling Car

डॉ. राजेन्द्र कुमार कसाना को मिला राष्ट्रीय सम्मान, We Care Media की ‘Hello Doctor’ मैगज़ीन का लोकार्पण

  • 362 views
डॉ. राजेन्द्र कुमार कसाना को मिला राष्ट्रीय सम्मान, We Care Media की ‘Hello Doctor’ मैगज़ीन का लोकार्पण

Hyundai Creta 2025 Top Model 10 साल में क्या बदला? | Creta Full Review | Creta S Optional | EV Cars

  • 526 views
Hyundai Creta 2025 Top Model 10 साल में क्या बदला? | Creta Full Review | Creta S Optional | EV Cars

Supreme Court Awaits Centre’s Stand on ‘Udaipur Files’; Notes Balance of Convenience Lies With Objectors

  • 88 views
Supreme Court Awaits Centre’s Stand on ‘Udaipur Files’; Notes Balance of Convenience Lies With Objectors

Air India to Review Preliminary Plane Crash Report with Pilots

  • 123 views
Air India to Review Preliminary Plane Crash Report with Pilots

Kia Syros Review | Kia Syros Price In India | Kia Syros 2025 | VR Auto Expert | Kia Syros Base Model

  • 190 views
Kia Syros Review | Kia Syros Price In India | Kia Syros 2025 | VR Auto Expert | Kia Syros Base Model

Kia Carens Clavis 2025 Full Review

  • 186 views
Kia Carens Clavis 2025 Full Review

Heart Attack Deaths in Hassan: A Local Trend or Cause for Wider Concern?

  • 119 views
Heart Attack Deaths in Hassan: A Local Trend or Cause for Wider Concern?