{"id":5571,"date":"2025-07-23T10:00:17","date_gmt":"2025-07-23T10:00:17","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/23\/cisa-warns-of-microsoft-sharepoint-code-injection-and-authentication-vulnerability-exploited-in-wild\/"},"modified":"2025-07-23T10:00:17","modified_gmt":"2025-07-23T10:00:17","slug":"cisa-warns-of-microsoft-sharepoint-code-injection-and-authentication-vulnerability-exploited-in-wild","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/23\/cisa-warns-of-microsoft-sharepoint-code-injection-and-authentication-vulnerability-exploited-in-wild\/","title":{"rendered":"CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild"},"content":{"rendered":"<p>    CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.\u00a0<\/p>\n<p>The vulnerabilities, designated as <a href=\"https:\/\/cybersecuritynews.com\/sharepoint-0-day-rce-vulnerability-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-49704<\/a> and CVE-2025-49706, pose significant risks to organizations running on-premises SharePoint servers and have been added to CISA\u2019s Known Exploited Vulnerabilities (KEV) catalog with an immediate remediation deadline.<\/p>\n<pre class=\"wp-block-preformatted\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0)\" class=\"has-inline-color has-vivid-cyan-blue-color\">Key Takeaways<\/mark><\/strong><br>1. CVE-2025-49704 and CVE-2025-49706 are being actively exploited to compromise SharePoint servers.<br>2.\u00a0 CISA requires immediate remediation by July 23, 2025.<br>3. Disconnect old SharePoint systems, patch current versions immediately.<\/pre>\n<h2 class=\"wp-block-heading\"><strong>Code Injection Vulnerability (CVE-2025-49704)<\/strong><\/h2>\n<p>CVE-2025-49704 represents a severe code injection vulnerability in Microsoft SharePoint that falls under the CWE-94 classification for Improper Control of Generation of Code.\u00a0<\/p>\n<p>This flaw allows authorized attackers to execute arbitrary code over a network connection, potentially giving them complete control over the affected SharePoint server.\u00a0<\/p>\n<p>The vulnerability enables threat actors to inject malicious code into the SharePoint application, which can then be executed with the privileges of the SharePoint service account, leading to potential system compromise and data exfiltration.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Improper Authentication Vulnerability (CVE-2025-49706)<\/strong><\/h2>\n<p><a href=\"https:\/\/cybersecuritynews.com\/microsoft-patch-tuesday-july-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-49706<\/a> is an improper authentication vulnerability classified under CWE-287 (Improper Authentication) that affects Microsoft SharePoint\u2019s authentication mechanisms.\u00a0<\/p>\n<p>This security flaw allows authorized attackers to perform spoofing attacks over a network, enabling them to impersonate legitimate users and bypass authentication controls.\u00a0<\/p>\n<p>Successful exploitation of this vulnerability grants attackers unauthorized access to view sensitive information and make modifications to disclosed data, effectively compromising the integrity and confidentiality of SharePoint environments.<\/p>\n<p>When the two vulnerabilities are chained together, they combine to form a powerful attack vector.\u00a0\u00a0<\/p>\n<p>Threat actors typically leverage CVE-2025-49706 first to bypass <a href=\"https:\/\/cybersecuritynews.com\/authentication\/\" target=\"_blank\" rel=\"noreferrer noopener\">authentication<\/a> mechanisms through spoofing techniques, then exploit CVE-2025-49704 to inject and execute malicious code on the compromised server.\u00a0<\/p>\n<p>Microsoft has confirmed that the update for CVE-2025-53770 includes more robust protections than the individual patches for these vulnerabilities, suggesting a comprehensive security enhancement approach that addresses the underlying architectural weaknesses.<\/p>\n<figure class=\"wp-block-table\">\n<table class=\"has-fixed-layout\">\n<tbody>\n<tr>\n<td><strong>CVE<\/strong><\/td>\n<td><strong>Title<\/strong><\/td>\n<td><strong>CVSS 3.1 Score<\/strong><\/td>\n<td><strong>Severity<\/strong><\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-49704<\/td>\n<td>Microsoft SharePoint Code Injection Vulnerability<\/td>\n<td>8.8<\/td>\n<td>Medium<\/td>\n<\/tr>\n<tr>\n<td>CVE-2025-49706<\/td>\n<td>Microsoft SharePoint Improper Authentication Vulnerability<\/td>\n<td>6.5<\/td>\n<td>Medium<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2 class=\"wp-block-heading\"><strong>CISA Issues 24-Hour Patch Deadline<\/strong><\/h2>\n<p>CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/20\/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">added both<\/a> vulnerabilities to the KEV catalog on July 22, 2025, with an unprecedented 24-hour remediation deadline set for July 23, 2025.\u00a0<\/p>\n<p>This aggressive timeline reflects the severity of active exploitation and the critical nature of the vulnerabilities.\u00a0<\/p>\n<p>The agency has issued specific guidance under Binding Operational Directive (BOD) 22-01, requiring federal agencies to immediately address these security flaws.<\/p>\n<p>Organizations are particularly vulnerable if they\u2019re running end-of-life (EOL) or end-of-service (EOS) SharePoint versions, including SharePoint Server 2013 and earlier releases that no longer receive security updates.\u00a0<\/p>\n<p>CISA emphasizes that these legacy systems should be completely disconnected from public-facing networks immediately.<\/p>\n<p><a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/20\/update-microsoft-releases-guidance-exploitation-sharepoint-vulnerabilities\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CISA recommends<\/a> a multi-layered approach to address these vulnerabilities. For supported SharePoint versions, organizations must apply the latest security patches and follow Microsoft\u2019s comprehensive mitigation guidance.\u00a0<\/p>\n<p>However, for EOL systems like SharePoint Server 2013, the only viable option is complete disconnection from network access.<\/p>\n<p>The agency\u2019s mitigation instructions reference multiple Microsoft security advisories and vulnerability databases, including the Microsoft Security Response Center (MSRC) and National Vulnerability Database (NVD).\u00a0<\/p>\n<p>Organizations should also consider implementing network segmentation, enhanced monitoring, and access controls as part of their broader cybersecurity posture to prevent similar exploitation attempts in the future.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\">Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;<strong>\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a>\u00a0<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cisa-sharepoint-code-injection\/\">CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cisa-sharepoint-code-injection\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.\u00a0 The vulnerabilities, designated as CVE-2025-49704 and CVE-2025-49706, pose significant risks to organizations running on-premises SharePoint servers and have been added to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-5571","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5571"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5571"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5571\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}