Site navigation

Microsoft Issues Critical Patches as Threat Actors Hit SharePoint

Graham Turner

,

SharePoint server hack
Microsoft warns that Chinese hackers are exploiting critical SharePoint server vulnerabilities, urging businesses to apply security patches immediately.

Microsoft has confirmed that state-backed Chinese threat actors have hacked on-premises SharePoint servers, targeting sensitive business data through newly discovered vulnerabilities.

The company has released critical security updates and is urging all customers using on-premises versions of SharePoint Server to patch their systems without delay.

Chinese Threat Actors Behind the Breach

Microsoft’s investigation links the attacks to three China-based hacking groups: Linen Typhoon, Violet Typhoon, and Storm-2603. These groups have exploited two severe vulnerabilities  – CVE-2025-49706, a spoofing flaw, and CVE-2025-49704, a remote code execution vulnerability – affecting on-premises SharePoint servers, but not SharePoint Online within Microsoft 365.

The company warned that the attacks are ongoing and likely to intensify. “We have high confidence that threat actors will continue to integrate these exploits into their attacks against unpatched on-premises SharePoint systems,” Microsoft said in a blog post.

How the Attacks Work

The attackers exploited SharePoint by sending crafted POST requests to vulnerable servers, allowing them to upload malicious scripts like spinstall0.aspx. These web shells enabled them to steal ASP.NET MachineKey data, which could then be used to maintain persistent access to compromised systems.

Microsoft’s telemetry shows that the hackers have also deployed PowerShell-based payloads post-exploitation, enabling the theft of encryption keys and other sensitive configuration data.


Recommended reading


Profile of the Threat Actors

  • Linen Typhoon, active since 2012, is focused on stealing intellectual property, particularly from organisations linked to government, defence, strategic planning, and human rights.

  • Violet Typhoon, active since 2015, specialises in espionage, targeting NGOs, think tanks, media organisations, higher education, and sectors like finance and healthcare across the US, Europe, and East Asia.

  • Storm-2603, assessed with “medium confidence” as a China-based group, has previously deployed ransomware strains such as Warlock and Lockbit but appears to be using these vulnerabilities primarily for key theft and long-term infiltration.

Microsoft’s Emergency Response

Microsoft’s Security Response Center (MSRC) has a comprehensive blog post detailing the attacks and the required security updates. Patches have been released for:

  • SharePoint Server Subscription Edition

  • SharePoint Server 2019

  • SharePoint Server 2016

The updates also address two new vulnerabilities, CVE-2025-53770 (remote code execution) and CVE-2025-53771 (security bypass), which are related to the original flaws.

To mitigate the risk of exploitation, Microsoft recommends:

  • Applying all available security updates immediately.

  • Rotating ASP.NET MachineKeys and restarting IIS services.

  • Enabling Antimalware Scan Interface (AMSI) and Microsoft Defender Antivirus in Full Mode on all SharePoint servers.

  • Deploying Microsoft Defender for Endpoint or equivalent endpoint protection tools.

If AMSI cannot be enabled, Microsoft suggests disconnecting vulnerable servers from the internet or placing them behind an authenticated proxy or VPN until patched.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data