TradeFlockUSA
Trending

Microsoft Confirms a Large SharePoint Attack with No Patch Yet.

Microsoft users are once again facing a security threat. This time, it isn’t limited to Outlook or Windows browsers, and unlike the recent Windows authentication relay vulnerability, there’s no patch or quick fix available. This is especially concerning for SharePoint Server users, as CVE-2025-53770 is currently experi

Divyakshi SainiStaff Writer
Microsoft Confirms a Large SharePoint Attack with No Patch Yet.

Microsoft users are once again facing a security threat. This time, it isn't limited to Outlook or Windows browsers, and unlike the recent Windows authentication relay vulnerability, there’s no patch or quick fix available. This is especially concerning for SharePoint Server users, as CVE-2025-53770 is currently experiencing widespread attacks, with on-premises servers worldwide being compromised. Here’s what you need to know and action steps to consider.

Microsoft Confirms CVE-2025-53770 Attacks on SharePoint Server

The security landscape has been busy, with Amazon notifying 220 million Prime customers of attacks and reports of a false alarm involving Ring doorbells going viral. These issues can be mitigated with basic security measures, but CVE-2025-53770, a recently discovered and confirmed vulnerability affecting SharePoint Server, is actively being exploited globally, according to Eye Security experts. Microsoft has acknowledged that it is aware of ongoing attacks, and more worryingly, no patch is currently available.

Also Read: Meta and Zuckerberg Settle to End the $8 billion Facebook Privacy Lawsuit

CVE-2025-53770, also known as ToolShell, is a critical flaw in on-premises SharePoint. It allows attackers to access and control servers without authentication, which is a very serious issue.

Researchers warned, "The risk is not just theoretical." Attackers can execute code remotely, even bypassing protections such as MFA or SSO. After gaining access, they can retrieve all SharePoint data, system files, and configurations, and move laterally within the Windows Domain.

Additionally, stealing cryptographic keys is a concern. Attackers can impersonate users or services even after the server is patched, making the issue persistent. When a patch is finally issued, likely as an emergency update, organizations will need to rotate secrets to invalidate malicious tokens.

Since SharePoint often connects to critical services like Outlook, Teams, and OneDrive, an exploited vulnerability could lead to data theft, password harvesting, and lateral network movement, as the researchers warned.

Share this article Latest News Categories More News

Divyakshi Saini

Staff Writer

TradeFlock USA correspondent.