Back to News
Market Impact: 0.6

Microsoft SharePoint servers under attack via zero-day vulnerability with no patch (CVE-2025-53770)

MSFTPANW
Cybersecurity & Data PrivacyTechnology & InnovationRegulation & LegislationInfrastructure & Defense
Microsoft SharePoint servers under attack via zero-day vulnerability with no patch (CVE-2025-53770)

Microsoft has confirmed that on-premises SharePoint Servers (2016, 2019, Subscription Edition) are under active zero-day exploitation via CVE-2025-53770, a variant of a previously patched RCE vulnerability, allowing unauthenticated remote code execution and full system takeover. Attackers are leveraging this to extract critical security keys, enabling persistence and user impersonation even after server patching, posing a severe risk of data theft and lateral movement across integrated services like Outlook and Teams. While no patch is currently available, Microsoft recommends configuring AMSI integration and deploying Defender AV; CISA has added this to its Known Exploited Vulnerabilities catalog, mandating federal agencies to mitigate by July 21st due to the ongoing active exploitation since July 18th.

Analysis

A critical, unpatched zero-day vulnerability (CVE-2025-53770) is being actively exploited in on-premises Microsoft SharePoint Servers (2016, 2019, and Subscription Edition), representing a significant security event with a corresponding negative sentiment score of -0.8 for Microsoft (MSFT). The exploit allows for unauthenticated remote code execution and, more critically, the theft of cryptographic security keys, enabling attackers to gain persistent access and impersonate users even after a patch is eventually applied. This elevates the incident's severity, as remediation for affected organizations is complex, costly, and requires a full rotation of system secrets, not just software updates. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has underscored the urgency by adding the vulnerability to its Known Exploited Vulnerabilities catalog. However, a crucial mitigating factor for Microsoft's overall financial outlook is that the vulnerability does not affect SharePoint Online, a core component of its strategic and high-growth Microsoft 365 cloud services. The impact is therefore largely contained to a legacy, on-premises customer base, limiting the direct financial fallout for the company despite the reputational damage.

AllMind AI Terminal