• Privacy Policy
  • Advertise
  • Contact Us
  • Login
Egy Economy
Advertisement
  • Egy Economy
  • Economy
    • Local
    • International
  • Stock Markets
    • Stock Exchange
    • Cash
  • Prices
  • Real Estate
  • Tech
  • Tourism
  • More
    • Opinions
    • Success Story
    • Variety
  • العربية
No Result
View All Result
  • Egy Economy
  • Economy
    • Local
    • International
  • Stock Markets
    • Stock Exchange
    • Cash
  • Prices
  • Real Estate
  • Tech
  • Tourism
  • More
    • Opinions
    • Success Story
    • Variety
  • العربية
No Result
View All Result
Egy Economy
No Result
View All Result
Home Tech

Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief

إيجى إيكونومى by إيجى إيكونومى
23 July، 2025
in Tech
0
Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief
153
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

Palo Alto Networks’ Unit 42 is tracking high-impact, ongoing threat activity targeting on-premises Microsoft SharePoint servers. While cloud environments remain unaffected, on-premises SharePoint deployments — particularly within government, schools, healthcare (including hospitals) and large enterprise companies — are at immediate risk.

CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 are a set of vulnerabilities that impact Microsoft SharePoint. CVE-2025-49704 and CVE-2025-49706, or CVE-2025-53770 and CVE-2025-53771 may be chained together, which can allow unauthenticated threat actors to access functionality that is normally restricted, to run arbitrary commands on vulnerable instances of Microsoft SharePoint.

In addition to the CVE reports, Microsoft has released further guidance on these vulnerabilities. The vulnerabilities, their CVSS scores and their descriptions are detailed in Table 1.

CVE Number Description CVSS Score

CVE-2025-49704

Improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 8.8

CVE-2025-49706

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5

CVE-2025-53770

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. 9.8

CVE-2025-53771

Improper limitation of a pathname to a restricted directory (path traversal) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5

Table 1. List of recent vulnerabilities affecting Microsoft SharePoint.

These vulnerabilities all apply to Microsoft SharePoint Enterprise Server 2016 and 2019. CVE-2025-49706 and CVE-2025-53770 also apply to Microsoft SharePoint Server Subscription Edition. Microsoft has stated that SharePoint Online in Microsoft 365 is not impacted.

We are currently working closely with the Microsoft Security Response Center (MSRC) to ensure that our customers have the latest information and we are actively notifying affected customers and other organizations. This situation is evolving rapidly, so it’s advisable to check Microsoft’s recommendations frequently.

We have observed active exploitation of these SharePoint vulnerabilities. Attackers are bypassing identity controls, including multi-factor authentication (MFA) and single sign-on (SSO), to gain privileged access. Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors and stealing cryptographic keys.

The attackers have leveraged these vulnerabilities to get into systems and in some cases are already establishing their foothold. If you have SharePoint on-premises exposed to the internet, you should assume that you have been compromised. Patching alone is insufficient to fully evict the threat.

We are urging organizations who are running vulnerable on-premises SharePoint to take the following actions immediately:

• Apply all relevant patches now and as they become available

• Rotate all cryptographic material

• Engage professional incident response

 

 

 

 

Tags: egyeconomyشركة Palo Alto networks

Related Posts

dubizzle Boosts Investor Trust During Periods of Uncertainty with the Launch of AI-Powered Property Valuation Tool “TruEstimate™”
Tech

dubizzle Boosts Investor Trust During Periods of Uncertainty with the Launch of AI-Powered Property Valuation Tool “TruEstimate™”

22 April، 2026
Ericsson unveils Differentiated Support: Modular, actionable intelligence
Tech

Ericsson unveils Differentiated Support: Modular, actionable intelligence

22 February، 2026
Ericsson and Mastercard enhance global digital money movement and accelerate digital financial inclusion
Tech

Ericsson and Mastercard enhance global digital money movement and accelerate digital financial inclusion

22 February، 2026
Microsoft and Ericsson bring enterprise-grade 5G laptop management to Windows 11
Tech

Microsoft and Ericsson bring enterprise-grade 5G laptop management to Windows 11

18 February، 2026
eNovate and Cobi Launch Large-Scale AI-Powered Digital Payment Infrastructure
Tech

eNovate and Cobi Launch Large-Scale AI-Powered Digital Payment Infrastructure

17 February، 2026
LG ELECTRONICS RELEASES FOURTH-QUARTER AND FULL-YEAR 2025 FINANCIAL RESULTS
Tech

LG ELECTRONICS RELEASES FOURTH-QUARTER AND FULL-YEAR 2025 FINANCIAL RESULTS

2 February، 2026
ADVERTISEMENT
No Result
View All Result

Recent Posts

  • LMD and Schneider Electric Sign Strategic MoU to Advance Smart and Sustainable Developments Across Egypt
  • Escalation Intensifies Across the Middle East as Attacks Expand; Egypt Condemns
  • Egyptian Pasta, Milling & Concentrates Launches 6-Pillar Sustainability Strategy to Reduce Carbon Footprint
  • Rising Tensions in the Gulf: Iran Accused of Targeting UAE Vessel and Fujairah Oil Facility as Egypt Condemns Escalation
  • Tanzanian Embassy in Cairo Celebrates 62nd Independence Anniversary with High-Level Diplomatic Attendance
  • EFG Hermes Appointed Sole Global Coordinator and Bookrunner for Misr Life Insurance IPO on EGX
  • TAMADON Developments unveils operations with a strategic vision to transform Egypt’s hotel investment landscape
  • Historic Surge in Oil Prices: Brent Nears 128 Dollars per Barrel Amid Escalating Tensions Around Iran
  • Sky Innovo Developments توقع اتفاقية استراتيجية مع Innovo Build لبدء الأعمال الإنشائية لمشروع Citystars Park St. باستثمارات 100 مليار جنيه
  • JPMorgan Acquires 5.66% Stake in Sibanye-Stillwater
  • XRP has achieved another weekly net inflow for the third time as institutional investors begin to show renewed interests as market sentiment flip positive
  • dubizzle Boosts Investor Trust During Periods of Uncertainty with the Launch of AI-Powered Property Valuation Tool “TruEstimate™”
  • Madaar Developments launches “The Hillage” with EGP 15 billion investment, introducing
  • Uranium Prices Remain Stable Thanks to Strong Outlook
  • Hometown Developments appoints Eng. Tarek Bahaa as CEO to bolster regional and international capabilities*
  • vivo Launches the V70,  Bringing Advanced Portrait Imaging to Every Lifestyle
  • Dubai leasing market adjusts as rental listings increase and tenant demand shifts
  • …Magdi Yacoub Heart Foundation Collaborated with Ricrac to Continue Advancing Free Cardiac Health care Services 
  • Nakheel launches LIVYN project in a prime location on Suez Road in Shorouk city
  • Madinet Masr delivers a standout FY 2025 performance, fueled by record new sales, accelerated deliveries across its flagship developments,

      Egy Economy

      © 2023 - إيجى إيكونومى.. بوابة إلكترونية متخصصة فى تغطية أخبار البيزنس والاقتصاد فى مصر والعالم العربى.

      روابط هامة

      • Egy Economy
      • Privacy Policy
      • Advertise
      • Contact Us

      تابعنا

      Welcome Back!

      Login to your account below

      Forgotten Password?

      Retrieve your password

      Please enter your username or email address to reset your password.

      Log In
      No Result
      View All Result
      • Egy Economy
      • Economy
        • Local
        • International
      • Stock Markets
        • Stock Exchange
        • Cash
      • Prices
      • Real Estate
      • Tech
      • Tourism
      • More
        • Opinions
        • Success Story
        • Variety
      • العربية

      © 2023 - إيجى إيكونومى.. بوابة إلكترونية متخصصة فى تغطية أخبار البيزنس والاقتصاد فى مصر والعالم العربى.

      -
      00:00
      00:00

      Queue

      Update Required Flash plugin
      -
      00:00
      00:00