Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Hackers target Microsoft SharePoint RCE chain with PoC exploit

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
microsoft
1 Posts 1 Posters 2 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Attackers have shifted focus to a chain of two Microsoft SharePoint vulnerabilities that, when combined, allow remote code execution on unpatched servers, according to threat intelligence firm Defused. The exploitation activity follows the public release of a proof-of-concept (PoC) that demonstrates how the two flaws can be chained together to bypass existing security measures.

    The first vulnerability in the chain is a deserialization issue that permits an authenticated attacker to trigger arbitrary code execution. The second flaw acts as an authentication bypass, allowing the attacker to reach the vulnerable deserialization endpoint without valid credentials. While Microsoft has released patches for both issues in recent updates, Defused reports that exploitation attempts are actively targeting organizations that have not yet applied the fixes.

    • The attack chain requires initial access to a SharePoint site, but the authentication bypass removes the need for privileged credentials.
    • Successful exploitation grants the attacker the ability to execute commands in the context of the SharePoint application pool.
    • Defused observed the PoC being weaponized in the wild shortly after its disclosure, with scans targeting internet-facing SharePoint servers.

    Defused advises administrators to prioritize patching all SharePoint servers immediately, as the exploit chain is now public and actively used. For organizations that cannot patch immediately, they recommend restricting network access to SharePoint services and monitoring for unusual process execution or web shell activity on affected hosts.

    Source: BleepingComputer

    Is your organization running any unpatched SharePoint instances, and how are you balancing the patch rollout with potential service downtime?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World