{"id":10461,"date":"2025-07-21T12:34:41","date_gmt":"2025-07-21T05:34:41","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10461"},"modified":"2026-02-05T12:34:48","modified_gmt":"2026-02-05T05:34:48","slug":"sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/21\/sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa\/","title":{"rendered":"SharePoint Server d\u00ednh l\u1ed7 h\u1ed5ng Zero-day, h\u00e0ng lo\u1ea1t h\u1ec7 th\u1ed1ng b\u1ecb hacker ki\u1ec3m so\u00e1t t\u1eeb xa"},"content":{"rendered":"<div style=\"text-align: justify\"><b>M\u1ed9t l\u1ed7 h\u1ed5ng zero-day (CVE-2025-53770) v\u1eeba \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong Microsoft SharePoint Server. L\u1ed7 h\u1ed5ng n\u00e0y \u0111ang b\u1ecb khai th\u00e1c quy m\u00f4 l\u1edbn ngo\u00e0i th\u1ef1c t\u1ebf, \u1ea3nh h\u01b0\u1edfng t\u1edbi h\u00e0ng ch\u1ee5c t\u1ed5 ch\u1ee9c, bao g\u1ed3m c\u1ea3 c\u00e1c c\u00f4ng ty \u0111a qu\u1ed1c gia v\u00e0 c\u01a1 quan ch\u00ednh ph\u1ee7. \u0110\u00e2y l\u00e0 m\u1ed9t cu\u1ed9c t\u1ea5n c\u00f4ng c\u00f3 t\u00ednh k\u1ef9 thu\u1eadt cao, kh\u00f3 ph\u00e1t hi\u1ec7n v\u00e0 c\u00f3 th\u1ec3 g\u00e2y ra h\u1eadu qu\u1ea3 nghi\u00eam tr\u1ecdng n\u1ebfu kh\u00f4ng \u0111\u01b0\u1ee3c x\u1eed l\u00fd k\u1ecbp th\u1eddi. <\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"1753087329043.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753087329043-png.17345\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753087329043.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753087329043-png.17345\/\" alt=\"1753087329043.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div style=\"text-align: justify\">\nL\u1ed7 h\u1ed5ng CVE-2025-53770 l\u00e0 m\u1ed9t bi\u1ebfn th\u1ec3 n\u00e2ng c\u1ea5p c\u1ee7a l\u1ed7 h\u1ed5ng CVE-2025-49704 (t\u1eebng \u0111\u01b0\u1ee3c Microsoft v\u00e1 h\u1ed3i \u0111\u1ea7u th\u00e1ng 7). Tuy nhi\u00ean, b\u1ea3n v\u00e1 tr\u01b0\u1edbc \u0111\u00f3 ch\u01b0a tri\u1ec7t \u0111\u1ec3 v\u00e0 \u0111\u00e3 b\u1ecb c\u00e1c nh\u00f3m tin t\u1eb7c t\u00ecm ra c\u00e1ch v\u01b0\u1ee3t qua.<\/p>\n<p>CVE-2025-53770 khai th\u00e1c m\u1ed9t l\u1ed7i trong qu\u00e1 tr\u00ecnh &#8220;deserialization&#8221;, khi SharePoint x\u1eed l\u00fd d\u1eef li\u1ec7u \u0111\u1ea7u v\u00e0o t\u1eeb b\u00ean ngo\u00e0i m\u00e0 kh\u00f4ng x\u00e1c th\u1ef1c \u0111\u1ea7y \u0111\u1ee7. \u0110i\u1ec1u n\u00e0y cho ph\u00e9p hacker th\u1ef1c thi m\u00e3 l\u1ec7nh t\u00f9y \u00fd t\u1eeb xa m\u00e0 kh\u00f4ng c\u1ea7n \u0111\u0103ng nh\u1eadp (unauthenticated RCE).<\/p>\n<p>C\u00f4ng ty c\u0169ng ti\u1ebft l\u1ed9 m\u1ed9t l\u1ed7 h\u1ed5ng n\u1eefa l\u00e0 CVE-2025-53771 m\u00e0 h\u1ecd cho bi\u1ebft c\u00f3 nhi\u1ec1u bi\u1ec7n ph\u00e1p b\u1ea3o v\u1ec7 h\u01a1n so v\u1edbi CVE-2025-49706. \u0110i\u1ec1u n\u00e0y cho th\u1ea5y c\u00f3 hai l\u1ed7 h\u1ed5ng zero-day m\u1edbi, c\u1ea3 hai \u0111\u1ec1u l\u00e0 l\u1ed7 h\u1ed5ng v\u01b0\u1ee3t qua c\u00e1c b\u1ea3n s\u1eeda l\u1ed7i ban \u0111\u1ea7u c\u1ee7a Microsoft v\u00e0o \u0111\u1ea7u th\u00e1ng n\u00e0y.<\/p>\n<p>Qu\u00e1 tr\u00ecnh t\u1ea5n c\u00f4ng \u0111i theo h\u01b0\u1edbng c\u1ef1c k\u1ef3 tinh vi:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Tin t\u1eb7c g\u1eedi m\u1ed9t y\u00eau c\u1ea7u \u0111\u1ed9c h\u1ea1i (payload) qua HTTP t\u1edbi SharePoint, l\u1ee3i d\u1ee5ng m\u1ed9t \u0111i\u1ec3m y\u1ebfu li\u00ean quan \u0111\u1ebfn header HTTP Referer.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Payload n\u00e0y ch\u1ee9a m\u00e3 \u0111\u1ed9c ASPX d\u00f9ng PowerShell \u0111\u1ec3 \u0103n c\u1eafp MachineKey (b\u1ed9 kh\u00f3a m\u00e3 h\u00f3a n\u1ed9i b\u1ed9 c\u1ee7a SharePoint)\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">V\u1edbi c\u00e1c kh\u00f3a n\u00e0y trong tay, k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 t\u1ea1o ra c\u00e1c \u0111o\u1ea1n m\u00e3 gi\u1ea3 m\u1ea1o d\u01b0\u1edbi d\u1ea1ng &#8220;VIEWSTATE&#8221; (m\u1ed9t c\u01a1 ch\u1ebf ASP.NET d\u00f9ng \u0111\u1ec3 l\u01b0u tr\u1ea1ng th\u00e1i gi\u1eefa c\u00e1c l\u1ea7n g\u1eedi\/nh\u1eadn d\u1eef li\u1ec7u).\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">C\u00e1c payload gi\u1ea3 m\u1ea1o n\u00e0y \u0111\u01b0\u1ee3c SharePoint ch\u1ea5p nh\u1eadn nh\u01b0 th\u1eadt v\u00e0 hacker c\u00f3 th\u1ec3 th\u1ef1c thi b\u1ea5t c\u1ee9 l\u1ec7nh g\u00ec tr\u00ean h\u1ec7 th\u1ed1ng, th\u1eadm ch\u00ed duy tr\u00ec quy\u1ec1n ki\u1ec3m so\u00e1t l\u00e2u d\u00e0i, di chuy\u1ec3n sang c\u00e1c h\u1ec7 th\u1ed1ng n\u1ed9i b\u1ed9 kh\u00e1c m\u00e0 kh\u00f4ng b\u1ecb ph\u00e1t hi\u1ec7n.\u200b<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">Theo th\u1ed1ng k\u00ea t\u1eeb gi\u1edbi chuy\u00ean gia:\u200b<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">\u00cdt nh\u1ea5t 85 m\u00e1y ch\u1ee7 SharePoint \u0111\u00e3 b\u1ecb x\u00e2m nh\u1eadp th\u00e0nh c\u00f4ng t\u00ednh \u0111\u1ebfn th\u1eddi \u0111i\u1ec3m hi\u1ec7n t\u1ea1i.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">C\u00e1c m\u00e1y ch\u1ee7 n\u00e0y thu\u1ed9c 29 t\u1ed5 ch\u1ee9c to\u00e0n c\u1ea7u bao g\u1ed3m c\u1ea3 c\u00e1c doanh nghi\u1ec7p l\u1edbn v\u00e0 c\u01a1 quan nh\u00e0 n\u01b0\u1edbc.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Kh\u00f4ng c\u1ea7n \u0111\u0103ng nh\u1eadp, kh\u00f4ng c\u1ea7n thao t\u00e1c t\u1eeb ng\u01b0\u1eddi d\u00f9ng, ch\u1ec9 c\u1ea7n h\u1ec7 th\u1ed1ng t\u1ed3n t\u1ea1i l\u1ed7 h\u1ed5ng v\u00e0 \u0111\u01b0\u1ee3c k\u1ebft n\u1ed1i internet l\u00e0 hacker \u0111\u00e3 c\u00f3 th\u1ec3 chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n to\u00e0n b\u1ed9 SharePoint Server t\u1eeb xa.\u200b<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\u0110\u1eb7c bi\u1ec7t, Microsoft x\u00e1c nh\u1eadn SharePoint Online (trong Microsoft 365) kh\u00f4ng b\u1ecb \u1ea3nh h\u01b0\u1edfng, ch\u1ec9 c\u00e1c h\u1ec7 th\u1ed1ng SharePoint on-premises (t\u1ef1 tri\u1ec3n khai t\u1ea1i ch\u1ed7) m\u1edbi b\u1ecb t\u1ea5n c\u00f4ng.<\/p>\n<p>V\u00ec sao l\u1ed7 h\u1ed5ng n\u00e0y c\u1ef1c k\u1ef3 nguy hi\u1ec3m?\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Th\u1ef1c thi m\u00e3 t\u1eeb xa kh\u00f4ng c\u1ea7n x\u00e1c th\u1ef1c, hacker c\u00f3 th\u1ec3 &#8220;chui&#8221; v\u00e0o m\u00e1y ch\u1ee7 m\u00e0 kh\u00f4ng c\u1ea7n m\u1eadt kh\u1ea9u.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">\u1ea8n m\u00ecnh r\u1ea5t kh\u00e9o, l\u1ee3i d\u1ee5ng c\u00e1c c\u01a1 ch\u1ebf n\u1ed9i b\u1ed9 \u0111\u1ec3 gi\u1ea3 d\u1ea1ng y\u00eau c\u1ea7u h\u1ee3p l\u1ec7.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Kh\u00f3 x\u1eed l\u00fd, v\u00ec sau khi b\u1ecb khai th\u00e1c, hacker c\u00f3 th\u1ec3 d\u00f9ng kh\u00f3a \u0111\u00e3 \u0103n c\u1eafp \u0111\u1ec3 ti\u1ebfp t\u1ee5c t\u1ea5n c\u00f4ng, ngay c\u1ea3 khi h\u1ec7 th\u1ed1ng \u0111\u00e3 v\u00e1 l\u1ed7i.\u200b<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\u0110\u00e3 c\u00f3 b\u1ea3n v\u00e1 ch\u00ednh th\u1ee9c cho CVE-2025-53770 v\u00e0 CVE-2025-53771, hai l\u1ed7 h\u1ed5ng m\u1edbi v\u00e1 l\u1ea1i c\u00e1c l\u1ed7i c\u0169 ch\u01b0a tri\u1ec7t \u0111\u1ec3. Ng\u01b0\u1eddi d\u00f9ng c\u1ea7n c\u1eadp nh\u1eadt ngay.<\/p>\n<p>N\u1ebfu ch\u01b0a th\u1ec3 c\u1eadp nh\u1eadt ngay:\u200b<\/p><\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">T\u1eaft k\u1ebft n\u1ed1i internet c\u1ee7a SharePoint Server t\u1ea1m th\u1eddi.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">K\u00edch ho\u1ea1t t\u00ednh n\u0103ng Antimalware Scan Interface (AMSI) c\u00f3 s\u1eb5n t\u1eeb b\u1ea3n c\u1eadp nh\u1eadt th\u00e1ng 9\/2023 tr\u1edf \u0111i.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">C\u00e0i \u0111\u1eb7t Microsoft Defender Antivirus v\u00e0 Defender for Endpoint \u0111\u1ec3 theo d\u00f5i h\u00e0nh vi sau khai th\u00e1c.\u200b<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">T\u0103ng c\u01b0\u1eddng gi\u00e1m s\u00e1t m\u1ea1ng v\u00e0 nh\u1eadt k\u00fd h\u1ec7 th\u1ed1ng, \u0111\u1eb7c bi\u1ec7t c\u00e1c truy c\u1eadp b\u1ea5t th\u01b0\u1eddng t\u1eeb c\u00f4ng c\u1ee5 nh\u01b0 PowerShell.\u200b<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">V\u1ee5 SharePoint l\u1ea7n n\u00e0y l\u00e0 minh ch\u1ee9ng \u0111i\u1ec3n h\u00ecnh cho m\u1ed9t lo\u1ea1i t\u1ea5n c\u00f4ng zero-day tinh vi, d\u1ec5 l\u1ecdt, kh\u00f3 ph\u00e1t hi\u1ec7n v\u00e0 kh\u00f3 kh\u1eafc ph\u1ee5c n\u1ebfu kh\u00f4ng c\u00f3 chu\u1ea9n b\u1ecb tr\u01b0\u1edbc.\u200b<\/div>\n<div style=\"text-align: right\"><b><i>WhiteHat t\u1ed5ng h\u1ee3p<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa.18584\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa.18584\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>M\u1ed9t l\u1ed7 h\u1ed5ng zero-day (CVE-2025-53770) v\u1eeba \u0111\u01b0\u1ee3c ph\u00e1t hi\u1ec7n trong Microsoft SharePoint Server. L\u1ed7 h\u1ed5ng n\u00e0y \u0111ang b\u1ecb khai th\u00e1c quy m\u00f4 l\u1edbn ngo\u00e0i th\u1ef1c t\u1ebf, \u1ea3nh h\u01b0\u1edfng t\u1edbi h\u00e0ng ch\u1ee5c t\u1ed5 ch\u1ee9c, bao g\u1ed3m c\u1ea3 c\u00e1c c\u00f4ng ty \u0111a qu\u1ed1c gia v\u00e0 c\u01a1 quan ch\u00ednh ph\u1ee7. \u0110\u00e2y l\u00e0 m\u1ed9t cu\u1ed9c t\u1ea5n c\u00f4ng c\u00f3 t\u00ednh [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10461","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10461"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10461\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}