Back to blog

Blog Post

Active Exploits Target SharePoint Servers

Share on social

Aug 1, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Active Exploits Target SharePoint Servers

[SharePoint Exploit]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

On July 19, 2025, Microsoft Security Response Center published a blog addressing active attacks against on-premises SharePoint servers that exploit CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution vulnerability. These vulnerabilities affect on-premises SharePoint servers only and do not affect SharePoint Online in Microsoft 365. Microsoft has released new comprehensive security updates for all supported versions of SharePoint Server (Subscription Edition, 2019, and 2016) that protect customers against these new vulnerabilities. Customers should apply these updates immediately to ensure they are protected.

These comprehensive security updates address newly disclosed security vulnerabilities in CVE-2025-53770 that are related to the previously disclosed vulnerability CVE-2025-49704. The updates also address the security bypass vulnerability CVE-2025-53771 for the previously disclosed CVE-2025-49706.

Three China-based threat groups, Linen Typhoon, Violet Typhoon, and Storm-2603, have been observed targeting exposed SharePoint infrastructure. Notably, Storm-2603 is now deploying Warlock ransomware following successful exploitation of disclosed vulnerabilities.

Storm-2603's attack chain includes:

  • Initial access via malicious POST requests exploiting CVE-2025-49706 and CVE-2025-49704.
  • Command execution via w3p.exe and enumeration using whoami.
  • Persistence through scheduled tasks and malicious .NET assemblies in IIS.
  • Credential access using Mimikatz targeting LSASS.
  • Lateral movement using PsExec and Impacket.
  • Payload delivery via modified GPOs to distribute Warlock ransomware.

Microsoft strongly recommends:

  • Installing all relevant security updates.
  • Enabling Antimalware Scan Interface (AMSI) in Full Mode.
  • Rotating ASP.NET machine keys.
  • Restarting IIS services.
  • Deploying Microsoft Defender for Endpoint of equivalent EDR solutions.
Lizzie Clark
LC

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient