ZeroHour
The Recordpublished ()ingested

Chinese nation-state groups exploiting SharePoint vulnerability, Microsoft confirms

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-49704
+1 in the same advisory: …49706
Authenticated Code Injection RCE in Microsoft SharePoint

CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.

Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.

8.8
group max
100% KEV ransomware
  • Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
Full article889 words · extracted from therecord.media · click to collapse

At least two Chinese nation-state threat groups are targeting internet-facing SharePoint servers via several recently disclosed vulnerabilities, Microsoft warned customers on Tuesday.  

In addition to the two confirmed nation-state groups — identified as Linen Typhoon and Violet Typhoon — Microsoft said it found another China-based group attacking SharePoint servers. 

The attribution follows an urgent alert about threat actors exploiting vulnerabilities in on-premises instances of Microsoft SharePoint, which thousands of organizations globally use to manage content, collaborate and share documents. The campaign of attacks set off alarms among defenders because of its use among governments, large corporations, universities and other sensitive entities. 

The bugs being used in the campaign against exposed SharePoint servers include CVE-2025-49706 and CVE-2025-49704. 

Microsoft also warned of two other vulnerabilities — CVE-2025-53770 and CVE-2025-53771 — that are of potential risk because they are bypasses for previous patches of CVE-2025-49706 and CVE-2025-49704.

On Monday, Charles Carmakal, CTO of Google-owned cybersecurity firm Mandiant, said that a “China-nexus threat actor” is one of several attackers targeting the vulnerabilities.

“It's critical to understand that multiple actors are now actively exploiting this vulnerability,” Carmakal said. “We fully anticipate that this trend will continue, as various other threat actors, driven by diverse motivations, will leverage this exploit as well."

Reuters reported on Tuesday that more than 100 organizations were affected by attacks through the vulnerabilities, which Microsoft was allegedly informed of in May. The bugs were discovered at a competition in Berlin by a cybersecurity official at Vietnamese military-owned telecom Viettel, and the researcher received a $100,000 bounty for finding them.

Microsoft released a patch earlier this month but hackers quickly found a way around the fixes, according to Reuters.

The Typhoons

Microsoft said the threat actors Linen Typhoon and Violet Typhoon, as well as a third Chinese group, have been exploiting CVE-2025-49706 and CVE-2025-49704 since July 7, using the bugs to gain access to organizations.

Linen Typhoon, also tracked as APT27, UNC215 and Red Phoenix, has been active since 2012, the company said, and has focused primarily on stealing intellectual property by attacking government organizations as well as defense companies and human rights groups. 

The group typically “has relied on existing exploits to compromise organizations,” Microsoft said.

The other confirmed threat actor, Violet Typhoon, is specifically dedicated to espionage and has previously targeted government officials, military personnel, think tanks, educational organizations, media companies and the health sector in the U.S., Europe and East Asia. 

Violet Typhoon, also tracked as APT31, has made a point of scanning the internet for vulnerabilities in the exposed web infrastructure of target organizations, exploiting whatever they discover to install tools that allow them to gain further access. 

Researchers are unsure of the motives of the third group, which has in the past used the Warlock and Lockbit ransomware strains.

Microsoft added that other groups and countries may use the bugs to target unpatched on-premises SharePoint systems and urged customers to install security updates released this week. 

The tech giant released security updates for all supported on-premises SharePoint Server versions and said cloud-hosted versions are not affected. 

‘Just beginning’

The situation began Saturday when Microsoft’s Security Response Center said it saw active attacks against on-premises SharePoint servers using multiple vulnerabilities. 

CISA added CVE-2025-53770 to its Known Exploited Vulnerabilities catalog on Sunday and ordered all federal civilian agencies to patch it by Monday. The agency added CVE-2025-49706 and CVE-2025-49704 on Tuesday and ordered agencies to patch them by Wednesday.

Multiple incident responders told Recorded Future News that exploitation is widespread and includes governments around the world. Hackers are using their access to exfiltrate data and gain a long-term foothold in victim organizations, they said.

The problem cannot be solved by simply patching the vulnerabilities, watchTowr CEO Benjamin Harris said, noting that attackers are stealing cryptographic keys that will allow for further access if they are not changed. 

Harris urged everyone to actually patch the bugs instead of only applying mitigations like an Antimalware Scan Interface (AMSI).

“Now that exploitation has been linked to nation-state actors, it would be naive to think they could leverage a SharePoint zero-day but somehow not bypass AMSI,” Harris said. 

The Washington Post reported that federal and state agencies have been affected by the campaign but the FBI and CISA did not respond to requests for confirmation. 

Several cybersecurity experts compared the SharePoint campaign to a similar one in 2021 affecting Microsoft Exchange servers that led to the compromise of U.S. government systems by Chinese actors

Cynthia Kaiser, former deputy director of the FBI’s Cyber Unit, warned that the SharePoint attacks will be an issue for months even if organizations have implemented patches because hackers “already in their systems may lie dormant for extended periods before operationalizing.”

“The real threat may be just beginning. Ransomware groups are known to rapidly operationalize disclosed vulnerabilities,” said Kaiser, who is now a senior official at cybersecurity firm Halcyon.

“In this case, the theft of authentication keys means attackers could potentially retain access even after patches are applied. This is a serious risk.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-sharepoint-vulnerabilities-china-groups-exploiting