{"id":11465,"date":"2025-07-21T12:34:20","date_gmt":"2025-07-21T05:34:20","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=11465"},"modified":"2026-06-25T09:59:57","modified_gmt":"2026-06-25T02:59:57","slug":"sharepoint-server-caught-zero-day-multiple-systems-controlled-by-remote-hackers","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/en\/2025\/07\/21\/sharepoint-server-caught-zero-day-multiple-systems-controlled-by-remote-hackers\/","title":{"rendered":"SharePoint Server Caught Zero-Day, Multiple Systems Controlled by Remote Hackers"},"content":{"rendered":"<div style=\"text-align: justify\"><b>A zero-day vulnerability (CVE-2025-53770) was recently discovered in Microsoft SharePoint Server. The vulnerability is being exploited on a large scale out of practice, affecting dozens of organizations, including multinational corporations and government agencies. This is a highly technical attack that can be difficult to detect and can have serious consequences if not addressed in a timely manner. <\/b><br \/>\n\u200b<\/div>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper js-lbImage\" title=\"1753087329043.png\" data-lb-caption-extra-html=\"\" data-lb-sidebar-href=\"\" data-single-image=\"1\" data-src=\"https:\/\/whitehat.vn\/attachments\/1753087329043-png.17345\/\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"1753087329043.png\" src=\"https:\/\/whitehat.vn\/attachments\/1753087329043-png.17345\/\" alt=\"1753087329043.png\" width=\"728\" height=\"380\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<div style=\"text-align: justify\">\n<p>The CVE-2025-53770 vulnerability is an upgraded variant of the CVC-49704 vulnerability (which was patched by Microsoft in early July). However, the previous patch was not thorough and was found to be surpassed by hacking groups.<\/p>\n<p>CVE-2025-53770 exploits an error during the &#8220;deserialization&#8221; process, when SharePoint handles external input data without full authentication. This allows hackers to execute arbitrary code remotely without login (unauthenticated RCE).<\/p>\n<p>The company also revealed another vulnerability, CVE-2025-53771, which it said had more protections than CV E-2 025 &#8211; 49706. This revealed two new zero-day vulnerabilities, both of which passed Microsoft&#8217;s initial bug fixes earlier this month.<\/p>\n<p>The attack process goes in extremely delicate direction:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">The hacker sends a malicious payload via HTTP to SharePoint, taking advantage of a weakness related to the HTP Referer header.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">This payload contains ASPX malicious code that PowerShell uses to steal MachineKey (SharePoint internal encryption key)<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">With these keys in hand, the attacker can generate rogue code as &#8220;VIEWSTATE&#8221; (an ASP.NET mechanism used to save status between data send\/receive).<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">These fake payloads are accepted as real by SharePoint and hackers can execute anything on the system, even maintaining long-term control, moving to other internal systems undetected.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">According to statistics from experts:<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">At least 85 SharePoint servers have been successfully hacked to date.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">These servers belong to 29 global organizations including large businesses and state agencies.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Without login, without manipulation from the user, as long as the system has a vulnerability and is connected to the internet, hackers can remotely gain control of the entire SharePoint Server.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>In particular, Microsoft confirmed that SharePoint Online (in Microsoft 365) was unaffected, and that only Sharepoint on-premises systems were attacked.<\/p>\n<p>Why is this hole so dangerous?<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Executing the code remotely doesn&#8217;t require authentication, and hackers can &#8220;hack&#8221; into servers without a password.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Hiding is clever, using internal mechanisms to disguise valid inquiries.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">This is difficult to handle, as after being exploited, hackers can use stolen keys to continue attacks, even after the system has been patched.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">\n<p>The official patches for CVE-2025-53770 and CVZ-1020-54771 are available, two new vulnerabilities patching old, incomplete errors. User needs update now.<\/p>\n<p>If you can&#8217;t update immediately:<\/p>\n<\/div>\n<ul>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Disable the internet connection of the temporary SharePoint Server.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Activates the Antimalware Scan Interface (AMSI) feature available from the September 2023 update onward.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Install the Microsoft Defender Antivirus and Defender for Endpoint to monitor post-exploitation behavior.<\/div>\n<\/li>\n<li data-xf-list-type=\"ul\">\n<div style=\"text-align: justify\">Enhanced network monitoring and system logging, especially unusual access from tools such as PowerShell.<\/div>\n<\/li>\n<\/ul>\n<div style=\"text-align: justify\">This SharePoint case exemplifies a type of zero-day attack that&#8217;s sophisticated, easy to leak, hard to detect and hard to fix without preparation.<\/div>\n<div style=\"text-align: right\"><b><i>Synthetic WhiteHat<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa.18584\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/sharepoint-server-dinh-lo-hong-zero-day-hang-loat-he-thong-bi-hacker-kiem-soat-tu-xa.18584\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A zero-day vulnerability (CVE-2025-53770) was recently discovered in Microsoft SharePoint Server. The vulnerability is being exploited on a large scale out of practice, affecting dozens of organizations, including multinational corporations and government agencies. This is a highly technical attack that can be difficult to detect and can have serious consequences if not addressed in a [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[351],"tags":[],"class_list":["post-11465","post","type-post","status-publish","format-standard","hentry","category-news-announcements"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11465","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=11465"}],"version-history":[{"count":2,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11465\/revisions"}],"predecessor-version":[{"id":11649,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/11465\/revisions\/11649"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=11465"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=11465"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=11465"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}