Concur News
  • Home
  • India
  • Startup
  • Regulation
  • Interview
  • Press Release
  • Login
September 5, 2025
No Result
View All Result
Concur News

Home » Microsoft SharePoint Zero-Day Exploit Affects 75 Servers; FBI Issues Warning

Microsoft SharePoint Zero-Day Exploit Affects 75 Servers; FBI Issues Warning

July 21, 2025
in Global, India, United States
Reading Time: 3 mins read
Microsoft SharePoint Zero-Day Exploit Affects 75 Servers; FBI Issues Warning
Share on LinkedinShare on Whatsapp

Critical Microsoft SharePoint Bug Lets Hackers Break Into 75 Servers — Including U.S. Agencies

Hackers are already actively misusing a dangerous new security flaw discovered in Microsoft SharePoint. This unpatched vulnerability, officially known as CVE-2025-53770, has led to a serious cyberattack affecting at least 75 servers, including systems belonging to large companies and even U.S. government bodies.

The vulnerability allows attackers to take full control of a SharePoint server without needing to log in. It takes advantage of the way SharePoint handles untrusted data and lets cybercriminals run harmful code remotely. This kind of remote code execution can allow hackers to steal sensitive information, upload malicious files, and maintain long-term access to an organization’s systems.

Consent Foundation

Microsoft Confirms the Threat

Microsoft has confirmed that the issue is real and ongoing. They are now working urgently to create a security update to fix the vulnerability. In a public statement, the company said:

“Our team is actively working to release a security update and will provide additional details as they are available.”

How Serious Is the Vulnerability?

Security experts rated this flaw 9.8 out of 10 on the Common Vulnerability Scoring System (CVSS), marking it as highly critical. According to cybersecurity researchers, attackers are already using this bug to steal encryption keys and install web shells—tools that give them full access to the affected servers.

Microsoft had already fixed an older bug called CVE-2025-49706 in its July 2025 security update, and interestingly, this new vulnerability is a variant of that bug.
However, hackers have found a new way to bypass the old patch and launch fresh attacks.

They are mainly using PowerShell scripts to upload malicious ASPX files that exploit a weakness in SharePoint’s MachineKey configuration.

Who Is Affected?

The issue does not impact cloud-based SharePoint Online (Microsoft 365) users. However, organizations using on-premises SharePoint Server 2016, 2019, or the Subscription Edition are at risk. With 75 servers already breached, experts are warning that the threat is widespread and ongoing.

What Has Microsoft Advised?

Until a proper patch is released, Microsoft has shared a few important safety tips for users managing SharePoint servers:

  1. Turn on Antimalware Scan Interface (AMSI) and make sure Microsoft Defender Antivirus is running on all SharePoint servers.
  2. If AMSI can’t be enabled, it’s best to disconnect the server from the internet temporarily.
  3. Use Microsoft Defender for Endpoint to detect any suspicious activities, such as unexpected ASPX files like spinstall0.aspx appearing on the server.

Final Words

This breach is another strong reminder that even trusted platforms like Microsoft SharePoint can have hidden weaknesses. IT teams running on-premises SharePoint servers should act immediately by applying Microsoft’s temporary defenses and watching for any unusual activity.

Microsoft has not yet released a fix, but they have confirmed it’s a top priority. Meanwhile, affected organizations are urged to remain alert, follow official guidelines, and prepare to patch their systems as soon as the update becomes available.

Also read: https://news.concur.live/indias-2027-digital-census-raises-fresh-concerns-over-privacy-and-social-equality/

Tags: Cyber securityData breachData privacy

Related Posts

Affordability Meets Privacy Risks in ChatGPT Go
India

Affordability Meets Privacy Risks in ChatGPT Go

September 3, 2025
Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw
Global

Data Protection Law Amendment to RTI Act Strikes Balance with Privacy Rights: Ashwini Vaishnaw

September 1, 2025
Raghuveer
Interview

Interview with Dr. Raghuveer Kaur, DPO at Cateina Technologies, on DPDPA, GRC, and Building Scalable Privacy Frameworks

August 29, 2025
70% of Parents Oppose Sharing Student Data with AI in K-12 Schools, Reports Reveal
Global

70% of Parents Oppose Sharing Student Data with AI in K-12 Schools, Reports Reveal

August 29, 2025

RECOMMENDED NEWS

HCLSoftware

HCLSoftware Unveils Domino 14.5, Prioritizing Data Privacy and Sovereign AI

2 months ago
Govt Adopts Zoho-Backed Email After Major Data Breach to Prevent Future Hacks

Govt Adopts Zoho-Backed Email After Major Data Breach to Prevent Future Hacks

1 month ago
Haryana’s Mandatory Pregnancy Registration Raises Privacy Concerns

Haryana’s Mandatory Pregnancy Registration Raises Privacy Concerns

5 months ago
AT&T

AT&T’s $177 Million Data Breach Settlement Gets Court Approval

2 months ago

BROWSE BY TOPICS

AI AI in education AI Privacy banks Children privacy Compliance Consent consent managers Cross-Border Cybercrime Cyber security Data Data breach Data leak Data privacy data privacy in education Data Protection Data security Data Violation Digital DPDP DPDPA DPDP Act EU Fines GDPR Generative AI google Hack Hacked Interview Investigation Law Meity penalty Personal data Press Release Privacy RBI SPAM Tech giants Technology TRAI Training Trending

701, The Capital, BKC(E), Mumbai, India

Follow us on social media:

Categories

Categories Layout
  • Africa
  • America
  • India
  • Asia
  • Europe
  • Japan
  • Business
  • Events
  • Regulation
  • Law
  • News
  • Privacy
  • Startup
  • Technology
Categories Layout
  • Apps
  • Cybercrime
  • Data
  • Data Breach
  • Data Privacy
  • Data Protection
  • Digital
  • FBI
  • Investment
  • Law
  • Privacy
  • Tech Giants
  • DPDP
  • DPDPA

Harmonize Data Compliance

Footer with Animated Button
Effortlessly align your data compliance with Concur, ensuring seamless integration and robust adherence to regulatory standards.
BOOK A DEMO
  • About
  • Advertise
  • Careers
  • Home
  • Demo

© 2025 Concur - consent manager

Welcome Back!

OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
  • Business

© 2025 Concur - consent manager