CVE-2025-49706
KEV ransomwarelargeImproper Authentication in Microsoft SharePoint Server (ToolShell Campaign)
CISA: Microsoft SharePoint Improper Authentication Vulnerability
CVE-2025-49706 is an improper authentication flaw (CWE-287) in Microsoft Office SharePoint that lets an unauthenticated remote attacker perform spoofing over a network; it requires no privileges or user interaction. On its own the bug allows an attacker to impersonate or authenticate improperly to SharePoint, but in the wild it has been used as part of the 'ToolShell' chain of five SharePoint vulnerabilities, where it is combined with related SharePoint flaws to gain unauthenticated remote code execution on servers. Any organization running on-premises SharePoint Server is in scope, with SharePoint Server 2013 and earlier being especially urgent because CISA notes they have reached end-of-life/end-of-service. Exploitation is active and severe: the flaw was added to the CISA KEV on 2025-07-22 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.1%, Microsoft has confirmed exploitation by Chinese nation-state groups, and roughly 400 victims — including U.S. federal agencies — have been hit, with actor Storm-2603 deploying a DNS-controlled backdoor and Warlock/LockBit ransomware.
What to do: Apply Microsoft's July 2025 security updates for SharePoint Server immediately, prioritizing internet-facing servers and any SharePoint Server 2013 or older instances. Disconnect from the internet (or restrict access) SharePoint versions that are EOL/EOS, since patches are not available, and follow the CISA and vendor mitigations referenced in the KEV entry, including the applicable BOD 22-01 guidance. Hunt for signs of compromise (spoofed/unexpected authentication, webshells, ransomware artifacts) and rotate SharePoint machine keys per Microsoft's guidance if compromise is suspected.
| microsoft sharepoint server | — |
| microsoft sharepoint enterprise server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- Affected
- Microsoft SharePoint
- Required action
- Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- sharepoint enterprise server, sharepoint server
- Weakness
- CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N