• Privacy Policy
  • Advertise
  • Contact Us
  • Login
Egy Economy
Advertisement
  • Egy Economy
  • Economy
    • Local
    • International
  • Stock Markets
    • Stock Exchange
    • Cash
  • Prices
  • Real Estate
  • Tech
  • Tourism
  • More
    • Opinions
    • Success Story
    • Variety
  • العربية
No Result
View All Result
  • Egy Economy
  • Economy
    • Local
    • International
  • Stock Markets
    • Stock Exchange
    • Cash
  • Prices
  • Real Estate
  • Tech
  • Tourism
  • More
    • Opinions
    • Success Story
    • Variety
  • العربية
No Result
View All Result
Egy Economy
No Result
View All Result
Home Tech

Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief

إيجى إيكونومى by إيجى إيكونومى
23 July، 2025
in Tech
0
Active Exploitation of Microsoft SharePoint Vulnerabilities: Threat Brief
153
SHARES
1.9k
VIEWS
Share on FacebookShare on Twitter

Palo Alto Networks’ Unit 42 is tracking high-impact, ongoing threat activity targeting on-premises Microsoft SharePoint servers. While cloud environments remain unaffected, on-premises SharePoint deployments — particularly within government, schools, healthcare (including hospitals) and large enterprise companies — are at immediate risk.

CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771 are a set of vulnerabilities that impact Microsoft SharePoint. CVE-2025-49704 and CVE-2025-49706, or CVE-2025-53770 and CVE-2025-53771 may be chained together, which can allow unauthenticated threat actors to access functionality that is normally restricted, to run arbitrary commands on vulnerable instances of Microsoft SharePoint.

In addition to the CVE reports, Microsoft has released further guidance on these vulnerabilities. The vulnerabilities, their CVSS scores and their descriptions are detailed in Table 1.

CVE Number Description CVSS Score

CVE-2025-49704

Improper control of generation of code (code injection) in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 8.8

CVE-2025-49706

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5

CVE-2025-53770

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. 9.8

CVE-2025-53771

Improper limitation of a pathname to a restricted directory (path traversal) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. 6.5

Table 1. List of recent vulnerabilities affecting Microsoft SharePoint.

These vulnerabilities all apply to Microsoft SharePoint Enterprise Server 2016 and 2019. CVE-2025-49706 and CVE-2025-53770 also apply to Microsoft SharePoint Server Subscription Edition. Microsoft has stated that SharePoint Online in Microsoft 365 is not impacted.

We are currently working closely with the Microsoft Security Response Center (MSRC) to ensure that our customers have the latest information and we are actively notifying affected customers and other organizations. This situation is evolving rapidly, so it’s advisable to check Microsoft’s recommendations frequently.

We have observed active exploitation of these SharePoint vulnerabilities. Attackers are bypassing identity controls, including multi-factor authentication (MFA) and single sign-on (SSO), to gain privileged access. Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors and stealing cryptographic keys.

The attackers have leveraged these vulnerabilities to get into systems and in some cases are already establishing their foothold. If you have SharePoint on-premises exposed to the internet, you should assume that you have been compromised. Patching alone is insufficient to fully evict the threat.

We are urging organizations who are running vulnerable on-premises SharePoint to take the following actions immediately:

• Apply all relevant patches now and as they become available

• Rotate all cryptographic material

• Engage professional incident response

 

 

 

 

Tags: egyeconomyشركة Palo Alto networks

Related Posts

EFG Hermes Leads Landmark EGP 5.1 Billion Corporate Bond Issuance for EFG Corp-Solutions, the Largest in Egypt’s Debt Capital Market
Tech

EFG Hermes Leads Landmark EGP 5.1 Billion Corporate Bond Issuance for EFG Corp-Solutions, the Largest in Egypt’s Debt Capital Market

4 June، 2026
Eid in Dubai Shop, Scan & Win Rewards Campaign gave away AED 200,000 among 25 Lucky Winners –
Tech

Eid in Dubai Shop, Scan & Win Rewards Campaign gave away AED 200,000 among 25 Lucky Winners –

3 June، 2026
Apple launch  queues turn into Cairo scenes… but this time in front of cardoO
Tech

Apple launch queues turn into Cairo scenes… but this time in front of cardoO

22 May، 2026
CSPs see major growth opportunity in AI and 5G — but implementation gap threatens progress
Tech

CSPs see major growth opportunity in AI and 5G — but implementation gap threatens progress

13 May، 2026
dubizzle Boosts Investor Trust During Periods of Uncertainty with the Launch of AI-Powered Property Valuation Tool “TruEstimate™”
Tech

dubizzle Boosts Investor Trust During Periods of Uncertainty with the Launch of AI-Powered Property Valuation Tool “TruEstimate™”

22 April، 2026
Ericsson unveils Differentiated Support: Modular, actionable intelligence
Tech

Ericsson unveils Differentiated Support: Modular, actionable intelligence

22 February، 2026
ADVERTISEMENT
No Result
View All Result

Recent Posts

  • Al Marasem International” launches a new real estate project in New Sheikh Zayed with “Egyptian-Saudi-Kuwaiti-UAE” investments exceeding 19 Billion Egyptian Pounds 
  • Capital Hills Developments completes delivering Park Yard 1..attracting international and Local brands to the project
  • Prime Hills Developments launches Prime Plaza Mall October with EGP 2.5bn investments
  • Valu and EBRD Expand Consumer Access to Energy-Efficient Household Solutions in Egypt
  • PLDG Development prepares to launch its latest project in West Cairo raising its projects portfolio to 9 
  • Kitchen Equipment Factory Showcases Hospitality Solutions at Benghazi Home & Hospitality Show 2026
  •  Gulf Egypt for Hotels and Tourism Announces New Expansion Strategy 
  • Eng Mohsen: Disciplined expansion, timely delivery, drive lasting trust in real estate 
  • Rock Developments Brings the FIFA World Cup Experience to Rock Gold Ahead of Its Grand Opening
  • IMKAN Misr Partners with Dex Squared Hospitality to Introduce Premium Holiday Homes Offering at Alburouj Through Dex Living
  • KDevelopments Contracts with NAMAA EXP as the Operational Consultant for Palencia Plaza.
  • Darak Group appoints Azur Hospitality to manage EGP 2.5bn Crystal Alamein and Marina Eye Residence developments
  • Trump’s Surprise Decision Calms Markets as Oil Falls and Gold Gives Up Gains After Cancellation of U.S. Strike on Iran
  • GEDIX Developments plans to reshape Sadat City’s urban landscape in collaboration with Archrete 
  • Aliaa Developments launches AI Tower in New Capital during a grand ceremony and signs multiple memoranda of understanding
  • ElRaay Developments Launches “River Park” Project in Obour City in Partnership with Al-Muwani Kuwaitiyah 
  • Master Zenouki and Zinox El Zenouki Online Sales Grow 36.3% This Year
  • AGEC Developments launches “June Handover Month” campaign for Ivy Residence in El Shorouk*
  • EFG Foundation, Bank NXT Foundation, and Valu Contribute to Expanding Care Capacity at Ahl Masr Burn Hospital
  • EFG Hermes Leads Landmark EGP 5.1 Billion Corporate Bond Issuance for EFG Corp-Solutions, the Largest in Egypt’s Debt Capital Market

      Egy Economy

      © 2023 - إيجى إيكونومى.. بوابة إلكترونية متخصصة فى تغطية أخبار البيزنس والاقتصاد فى مصر والعالم العربى.

      روابط هامة

      • Egy Economy
      • Privacy Policy
      • Advertise
      • Contact Us

      تابعنا

      Welcome Back!

      Login to your account below

      Forgotten Password?

      Retrieve your password

      Please enter your username or email address to reset your password.

      Log In
      No Result
      View All Result
      • Egy Economy
      • Economy
        • Local
        • International
      • Stock Markets
        • Stock Exchange
        • Cash
      • Prices
      • Real Estate
      • Tech
      • Tourism
      • More
        • Opinions
        • Success Story
        • Variety
      • العربية

      © 2023 - إيجى إيكونومى.. بوابة إلكترونية متخصصة فى تغطية أخبار البيزنس والاقتصاد فى مصر والعالم العربى.

      -
      00:00
      00:00

      Queue

      Update Required Flash plugin
      -
      00:00
      00:00