{"id":5510,"date":"2025-07-21T10:06:09","date_gmt":"2025-07-21T10:06:09","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/21\/microsoft-released-emergency-security-update-to-patch-critical-sharepoint-0-day-vulnerability\/"},"modified":"2025-07-21T10:06:09","modified_gmt":"2025-07-21T10:06:09","slug":"microsoft-released-emergency-security-update-to-patch-critical-sharepoint-0-day-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/21\/microsoft-released-emergency-security-update-to-patch-critical-sharepoint-0-day-vulnerability\/","title":{"rendered":"Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability"},"content":{"rendered":"<p>    Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are <a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-rce-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">actively exploiting<\/a>.\u00a0<\/p>\n<p>The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation.<\/p>\n<pre class=\"wp-block-preformatted\"><strong>Key Takeaways<\/strong><br>1. Active zero-day attacks targeting on-premises SharePoint servers via CVE-2025-53770 and CVE-2025-53771.<br>2. Apply security updates immediately: KB5002768 (Subscription Edition) or KB5002754 (SharePoint 2019).<br>3. Microsoft Defender is deployed with threat detection and hunting capabilities.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Zero-Day Vulnerabilities Under Active Exploitation<\/strong><\/h2>\n<p>The security flaws specifically target on-premises SharePoint Server installations, while SharePoint Online in <a href=\"https:\/\/cybersecuritynews.com\/microsoft-enhance-microsoft-365-security\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft 365<\/a> remains unaffected.\u00a0<\/p>\n<p>Microsoft\u2019s Security Response Center confirmed that threat actors are actively exploiting these vulnerabilities, which were only partially addressed in the initial July 2025 Security Update.\u00a0<\/p>\n<p>The vulnerabilities enable attackers to achieve remote code execution and potentially compromise entire SharePoint environments.<\/p>\n<p>Security researchers have identified that successful exploitation results in the creation of malicious files such as spinstall0.aspx, which serves as an indicator of compromise.\u00a0<\/p>\n<p>The attack vectors involve sophisticated techniques that bypass traditional security controls, making immediate patching critical for organizational security.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>Affected Products<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-53770<\/p>\n<p>CVE-2025-53771<\/td>\n<td>SharePoint Server Remote Code Execution Vulnerability<\/td>\n<td>SharePoint Server 2016, 2019, Subscription Edition<\/td>\n<td>Critical<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>Security Updates<\/strong><\/h2>\n<p>Microsoft has <a href=\"https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/\" target=\"_blank\" rel=\"noreferrer noopener\">released<\/a> comprehensive security updates to address these vulnerabilities. For SharePoint Server Subscription Edition, organizations must apply security update KB5002768, while SharePoint Server 2019 requires KB5002754.\u00a0<\/p>\n<p>SharePoint 2016 updates are still in development, leaving these systems temporarily vulnerable.<\/p>\n<p>The company recommends implementing multiple defensive layers immediately. Organizations must enable the Antimalware Scan Interface (AMSI) in Full Mode, which provides critical protection against unauthenticated attacks.\u00a0<\/p>\n<p>Additionally, deploying Microsoft Defender Antivirus on all SharePoint servers creates an essential security barrier.<\/p>\n<p>A crucial post-patching step involves rotating SharePoint Server ASP.NET machine keys using either the Update-SPMachineKey PowerShell cmdlet or the Central Administration interface.\u00a0<\/p>\n<p>After key rotation, administrators must restart IIS using iisreset.exe on all SharePoint servers to complete the remediation process.<\/p>\n<p>Microsoft has deployed multiple detection mechanisms through its security ecosystem. <a href=\"https:\/\/cybersecuritynews.com\/microsoft-defender-spoofing-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Defender<\/a> Antivirus now identifies threats under detection names Exploit:Script\/SuspSignoutReq.A and Trojan:Win32\/HijackSharePointServer.A.\u00a0<\/p>\n<p>These signatures provide real-time protection against known exploitation attempts.<\/p>\n<p>Microsoft Defender for Endpoint generates specific alerts, including \u201cPossible web shell installation,\u201d \u201cSuspicious IIS worker process behavior,\u201d and \u201cSuspSignoutReq malware was blocked on a SharePoint server\u201d.\u00a0<\/p>\n<p>Security teams can leverage advanced hunting queries to identify potential compromise indicators across their environment.<\/p>\n<p>Organizations can utilize Microsoft Defender Vulnerability Management to assess exposure levels by filtering for the specific <a href=\"https:\/\/cybersecuritynews.com\/cisa-provides-last-minute-support\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE identifiers<\/a> in the Software vulnerabilities section.\u00a0<\/p>\n<p>The unified advanced hunting query DeviceTvmSoftwareVulnerabilities | where CveId in (\u201cCVE-2025-49706\u2033,\u201dCVE-2025-53770\u201d) enables comprehensive vulnerability tracking across enterprise environments.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\">Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;<strong>\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a>\u00a0<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/microsoft-security-update-sharepoint-0-day\/\">Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/microsoft-security-update-sharepoint-0-day\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting.\u00a0 The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key Takeaways1. Active zero-day attacks [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158],"tags":[130],"class_list":["post-5510","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5510"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5510"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5510\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}