TTB White LOGO TB
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Trending
Chrome for iOS: Enterprise Work/Personal Account Switching Launches
Google Gemini Crypto Guide: Turn News into Trade Signals
Global Microsoft SharePoint Zero-Day Attack: Patches, Impact, Mitigation
WhatsApp Replaces Native Windows App with Web Wrapper
Apple to Reveal iPad Pro with Two Front Cameras in Late 2025
Tuesday, Jul 22, 2025
The Tech BasicThe Tech Basic
Font ResizerAa
Search
  • News
  • PC & Hardware
  • Mobiles
  • Gaming
  • Electronics
  • Gadget
  • Reviews
  • How To
Follow US
Microsoft SharePoint
The Tech Basic > News > Global Microsoft SharePoint Zero-Day Attack: Patches, Impact, Mitigation
News

Global Microsoft SharePoint Zero-Day Attack: Patches, Impact, Mitigation

Salman Akhtar
Last updated: 22 July 2025 03:40
Salman Akhtar
Share
Image Source: SC Media
SHARE

Microsoft has warned of active attacks exploiting a critical zero‑day vulnerability in on‑premises SharePoint Server discovered by security researchers at Eye Security on July 18, 2025. The flaw enables unauthenticated actors to access certain server versions and extract keys that allow them to impersonate users or services even after a server reboot or patch application.

Contents
How the vulnerability worksRisk to connected servicesAvailable patches and timelineUrgent mitigation adviceKnown victims and scopeNext steps for defenders
Microsoft SharePoint
Image Source: CSO Online

How the vulnerability works

The exploit combines two bugs first demonstrated at the Pwn2Own contest in May. Attackers can send specially crafted requests to a vulnerable SharePoint instance that trigger deserialization of untrusted data. This grants remote code execution and access to cryptographic material used by the server. Once the keys are stolen, attackers can maintain persistence on the network despite remediation efforts.

Risk to connected services

Many organizations link their on‑prem SharePoint servers to other Microsoft products such as Outlook Teams and OneDrive. An attacker with stolen credentials can move laterally across these platforms, harvesting sensitive data and escalating privileges. Cloud-based SharePoint in Microsoft 365 is not affected by this zero‑day.

Available patches and timeline

Microsoft has released security updates that fully protect SharePoint 2019 and SharePoint Subscription Edition servers. A patch for SharePoint 2016 is in final testing and expected soon. Administrators should apply the latest updates immediately and confirm successful installation.

Urgent mitigation advice

Cybersecurity and Infrastructure Security Agency suggests turning off the affected servers to the internet when no enterprising solution has been implemented. Organizations that cannot install updates must at least block ports that SharePoint uses and keep track of logs where unexpected activity is detected.

Known victims and scope

Identified victims are USA federal and state agencies, universities, energy providers, and an Asian telecommunications company. These developers caution that other parts of the world are still vulnerable to tens of thousands of SharePoint implementations.

Microsoft Sharepoint
Image Source: Fixinc

Next steps for defenders

Security teams should retrieve indicators of compromise from Eye Security’s analysis and hunt for the malicious ASPX payload and unusual HTTP referer values. Logs around the ToolPane endpoint merit careful review. Applying the published mitigations and conducting thorough forensic exams are essential to clear any lingering backdoors.

The fact that this zero-day remained persistent highlights the importance of minute monitoring and quick patching in on-prem infrastructures. Companies have to experience this vulnerability as the highest priority in order to avoid further loss of data and disruption of services.

TAGGED:Microsoft
Share This Article
Facebook Reddit Copy Link Print
Share
Salman Akhtar
By Salman Akhtar
View enlightening tech pieces written by Salman Keep up with the most recent news, advice, and trends in the field of technology.

Let's Connect

FacebookLike
XFollow
PinterestPin
InstagramFollow
Google NewsFollow
FlipboardFollow

Popular Posts

Chrome

Chrome for iOS: Enterprise Work/Personal Account Switching Launches

Salman Akhtar
Google Gemini

Google Gemini Crypto Guide: Turn News into Trade Signals

Salman Akhtar
WhatsApp

WhatsApp Replaces Native Windows App with Web Wrapper

Salman Akhtar
iPad Pro

Apple to Reveal iPad Pro with Two Front Cameras in Late 2025

Salman Akhtar

You Might Also Like

Windows 11
News

Microsoft Introduces Background Preloading for Word on Windows 11

Copilot on Windows 11
News

Microsoft Tests Full Desktop Sharing with Copilot on Windows 11

Microsoft
News

Perfect Dark and Everwild Canceled in Microsoft’s Studio Purge

Windows
News

Windows Blue Screen of Death Replaced by Black Error Screen in 2025 Update

Social Networks

Facebook-f Twitter Instagram Pinterest Rss

Company

  • About Us
  • Our Team
  • Contact Us

Policies

  • Disclaimer
  • Privacy Policy
  • Cookies Policy
Latest
Meta Rejects EU AI Code: Regulatory Showdown Escalates
Apple Sues Jon Prosser Over Theft of iOS 26 Trade Secrets
Apple Patent Shows Digital Crown Can Sense Touch and Light
Anthropic Tightens Claude Code Limits Without Warning Users
OpenAI Launches Agent Mode in ChatGPT for Pro and Plus Users

© 2024 The Tech Basic INC. 700 – 2 Park Avenue New York, NY.

TTB White LOGO TB
Follow US
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?