ZeroHour

CVE-2025-49706

KEV ransomwarelarge

Improper Authentication in Microsoft SharePoint Server (ToolShell Campaign)

CISA: Microsoft SharePoint Improper Authentication Vulnerability

CVSS 3.1
6.5 medium
EPSS
99%p100
Published
()
KEV added
AI analysis

CVE-2025-49706 is an improper authentication flaw (CWE-287) in Microsoft Office SharePoint that lets an unauthenticated remote attacker perform spoofing over a network; it requires no privileges or user interaction. On its own the bug allows an attacker to impersonate or authenticate improperly to SharePoint, but in the wild it has been used as part of the 'ToolShell' chain of five SharePoint vulnerabilities, where it is combined with related SharePoint flaws to gain unauthenticated remote code execution on servers. Any organization running on-premises SharePoint Server is in scope, with SharePoint Server 2013 and earlier being especially urgent because CISA notes they have reached end-of-life/end-of-service. Exploitation is active and severe: the flaw was added to the CISA KEV on 2025-07-22 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.1%, Microsoft has confirmed exploitation by Chinese nation-state groups, and roughly 400 victims — including U.S. federal agencies — have been hit, with actor Storm-2603 deploying a DNS-controlled backdoor and Warlock/LockBit ransomware.

What to do: Apply Microsoft's July 2025 security updates for SharePoint Server immediately, prioritizing internet-facing servers and any SharePoint Server 2013 or older instances. Disconnect from the internet (or restrict access) SharePoint versions that are EOL/EOS, since patches are not available, and follow the CISA and vendor mitigations referenced in the KEV entry, including the applicable BOD 22-01 guidance. Hunt for signs of compromise (spoofed/unexpected authentication, webshells, ransomware artifacts) and rotate SharePoint machine keys per Microsoft's guidance if compromise is suspected.

Affected
microsoft sharepoint server
microsoft sharepoint enterprise server
Estimated exposure
largetens of thousands of on-premises SharePoint Server deployments, with thousands of servers directly internet-exposed (estimated) — Estimate based on SharePoint Server's wide enterprise self-hosted install base and July 2025 public internet scans showing thousands of internet-exposed SharePoint endpoints; SharePoint Online is not indicated as affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CISA Known Exploited Vulnerability
Affected
Microsoft SharePoint
Required action
Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Due date
Ransomware use
Known
Vendors
microsoft
Products
sharepoint enterprise server, sharepoint server
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news