Microsoft pins on-prem SharePoint attacks on Chinese threat actors
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-49704 +1 in the same advisory: …49706 | Authenticated Code Injection RCE in Microsoft SharePoint CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented. Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers. | 8.8 group max | 100% | KEV ransomware |
| masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments… | |
| CVE-2025-53770 | Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days. Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×3 |
| mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users | |
| CVE-2025-53771 | Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies. Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed. | 6.5 | 100% |
| largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | asp.net | on such as Defender Antivirus, and Rotate SharePoint Server ASP.NET machine keys Before doing that, though, they should check w |
Full article726 words · extracted from helpnetsecurity.com · click to collapse
This is a developing story, new update here:
Storm-2603 spotted deploying ransomware on exploited SharePoint servers

As Microsoft continues to update its customer guidance for protecting on-prem SharePoint servers against the latest in-the-wild attacks, more security firms have begun sharing details about the ones they have detected.

Most intriguingly, Check Point Research says that they observed the first exploitation attempts on July 7th, with the target being a major Western government.
That date not only precedes the publication of the screenshot of the ToolShell exploit chain (CVE-2025-49706 + CVE-2025-49704) in action and that of additional technical details, but also the date of the release of the patches for those flaws.
Updated guidance
While Microsoft initially stated that the active attacks targeting on-premises SharePoint Server customers are exploiting a variant of CVE-2025-49706, i.e., CVE-2025-53770, it has now confirmed that:
- CVE-2025-53770 is related to CVE-2025-49704, and
- CVE-2025-53771 to CVE-2025-49706.
(CVE-2025-53770 is, according to Microsoft’s security advisory, being exploited, but CVE-2025-53771 – again, according to its advisory – is not.)
In the meantime, the company has released security updates that fix both CVE-2025-53770 and CVE-2025-53771 on Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019, and Microsoft SharePoint Enterprise Server 2016, and is advising customers with on-prem servers to:
- Implement them
- Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
- Turn on and correctly configure the Antimalware Scan Interface (AMSI) and use an antivirus solution such as Defender Antivirus, and
- Rotate SharePoint Server ASP.NET machine keys
Before doing that, though, they should check whether their servers have been targeted and compromised.
Different attack clusters
Eye Security continues to update a list of indicators of compromise related to the different waves of attacks they spotted since July 17 up to now – including the newest ones that emerged on Monday, after a proof-of-concept exploit script for CVE-2025-53770 was published on Github.
Trend Micro, Rapid7 and Bitdefender have detected the same attacks. “Attackers are bypassing identity controls, including multi-factor authentication (MFA) and single sign-on (SSO), to gain privileged access. Once inside, they’re exfiltrating sensitive data, deploying persistent backdoors and stealing cryptographic keys,” Palo Alto Networks’ researchers have noted.
Check Point and SentinelOne researchers have also detected others.
As mentioned before – and as confirmed to us by a Check Point representative – they observed single exploitation attempts on July 7th and 10th, and then significant exploitation waves starting July 17th.
The exploitation attempt on July 7th targeted a Western government. The waves that started on July 17th and intensified on July 18th and 19th delivered a custom webshell and targeted organizations in the government, software, and telecommunications sectors, predominantly in Northern America and Europe.
One of the IP addresses involved in the latter attacks was also associated with earlier exploitation attempts against a related Ivanti EPMM vulnerability chain, they noted.
SentinelOne researchers have also observed exploitation attempts from three distinct attack clusters, some involving the deployment of webshells and one not. (The sophistication of the latter attempt made them believe that this attack was performed either as a skilled red team emulation exercise or was the “work of a capable threat actor with a focus on evasive access and credential harvesting.”)
They also said that they have observed multiple state-aligned threat actors – unrelated to the first wave of exploitation – beginning to engage in reconnaissance and early-stage exploitation activities.
“Additionally, we’ve also identified actors possibly standing up decoy honeypot environments to collect and test exploit implementations, as well as sharing tooling and tradecraft across known sharing platforms. As awareness spreads within these communities, we expect further weaponization and sustained targeting of vulnerable SharePoint infrastructure,” SentinelOne researchers added.
Microsoft’s threat intelligence team said today that it has observed “two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon” and another, unnamed China-based threat actor (tracked as Storm-2603) exploiting CVE-2025-49706 and CVE-2025-49704, and has shared indicators of compromise, hunting queries, and more.
Organizations that haven’t updated their on-prem SharePoint Server instances since before Microsoft’s July 2025 Patch Tuesday releases should consider them compromised and move to investigate and remediate discovered intrusions.
UPDATE (July 23, 2025, 11:20 a.m. ET):
CISA has added CVE-2025-49704 and CVE-2025-49706 to the Known Exploited Vulnerabilities catalog.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/07/22/microsoft-pins-sharepoint-attacks-cve-2025-53770/