Your SharePoint System Under Direct Attack

  • JULY 22ND, 2025
  • 3min read
Your SharePoint System Under Direct Attack

Introduction

If your organisation uses on-premise Microsoft SharePoint servers, your systems are currently under direct and active threat. Security researchers have observed cybercriminals actively exploiting new vulnerabilities to compromise SharePoint deployments worldwide. This isn’t a future risk; it’s happening now.

These critical flaws (tracked as CVE-2025-53770 and CVE-2025-53771) stem from incomplete fixes for earlier vulnerabilities. This means even if you applied previous patches, your SharePoint might still be exposed. Microsoft confirmed these issues on July 19th, 2025, releasing urgent security bulletins and patches: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53770 Don’t delay. Your organisation could be next.

The Critical Threat Explained

Attackers are exploiting these SharePoint vulnerabilities to:

  • Upload Malicious Files: They can remotely upload harmful files onto your SharePoint server.
  • Steal Sensitive Data: These files allow them to extract critical “secrets” (like cryptographic keys) from your SharePoint instance.
  • Gain Full Control: Using the stolen information, attackers can then achieve unauthenticated remote control over your SharePoint server. This means they can compromise your data, disrupt operations, or use your server as a launchpad for further attacks, all without needing your login credentials.

These attacks have already been observed across diverse sectors, including finance, education, energy, and healthcare.

Urgent Actions Required: Protect Your SharePoint Now

Organisations with on-premise SharePoint deployments (SharePoint Subscription Edition, Server 2019, Server 2016) must act immediately:

  • Apply Latest Security Updates: This is critical. Immediately apply all available Microsoft security updates for your SharePoint Server versions. (Note: A patch for Server 2016 is pending, so rigorous monitoring is even more vital for these versions.).
  • Rotate Machine Keys: After patching, immediately rotate your SharePoint Server ASP.NET machine keys. This crucial step prevents attackers who may have already stolen these keys from maintaining access even after your systems are patched.
  • Monitor for Unauthorised Files: Actively check your SharePoint’s /layouts/ directory for any unexpected or malicious .aspx files (like spinstall0.aspx). Remove any found immediately.
  • Audit Configuration Changes: Regularly inspect your SharePoint configuration files for any suspicious or unauthorised modifications.
  • Review Server Logs: Look for unusual access patterns, especially those involving the ToolPane.aspx endpoint or suspicious __VIEWSTATE activity in your server logs. This could indicate an ongoing attack attempt.
  • Disconnect (If Necessary): If immediate patching and key rotation are not possible, consider temporarily disconnecting public-facing SharePoint servers from the internet to prevent compromise.
  • Implement Layered Security: Ensure you have robust firewalls, intrusion prevention systems, and endpoint detection and response tools for additional layers of defence.

Conclusion: Act Fast to Secure Your Data

The active exploitation of these SharePoint vulnerabilities highlights the speed and persistence of modern cyber threats. Your organisation’s data, operations, and reputation are at risk. Proactive patching, immediate key rotation, and vigilant monitoring are not optional; they are immediate necessities. Don’t let your SharePoint become an easy target.

Never miss a CIL Security Advisory

Stay informed with the latest security updates and insights from CIL.

Your SharePoint System Under Direct Attack

Contact Us

Message Sent!

Thank you for reaching out. We have received your message and will get back to you shortly.

Check your email for a confirmation from us.

Start a project

Project Request Submitted!

Thank you for your interest. Our team will review your project details and reach out to you soon.

Check your email for a confirmation from us.