Back to News
Market Impact: 0.55

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

MSFTPANW
Cybersecurity & Data PrivacyTechnology & Innovation
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

A critical zero-day vulnerability (CVE-2025-53770) in on-premises Microsoft SharePoint is being actively exploited, compromising at least 85 servers across 29 organizations, including multi-nationals and government entities, since July 18th. Attackers are leveraging a variant of a Pwn2Own-demonstrated flaw to achieve Remote Code Execution by stealing server MachineKey configurations, with Microsoft currently working on a patch. This poses a significant and immediate operational and data security risk for affected enterprises, underscoring the critical need for robust cybersecurity measures and vigilance against unpatched vulnerabilities.

Analysis

A critical, unpatched zero-day vulnerability (CVE-2025-53770) in on-premises Microsoft SharePoint servers is under active exploitation, representing a significant and immediate risk for enterprise customers. Since July 18th, attackers have compromised at least 85 servers across 29 organizations, including multi-national corporations and government entities, by leveraging a variant of a previously disclosed Pwn2Own exploit to achieve Remote Code Execution. The attack's method involves stealing the server's MachineKey to forge valid security tokens, demonstrating a sophisticated threat. While Microsoft (MSFT) has acknowledged the issue and is developing a patch, the lack of an immediate fix forces customers into disruptive mitigations, such as disconnecting servers from the internet if they cannot enable AMSI integration. Critically, this vulnerability does not affect the strategic Microsoft 365 cloud platform, which contains the financial impact for Microsoft but underscores the persistent security risks and high operational costs associated with legacy on-premises software. The strongly negative sentiment (-0.8 for MSFT) reflects the reputational risk and the severity of the threat to its enterprise client base.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.80

Ticker Sentiment

MSFT-0.80
PANW0.00

Key Decisions for Investors

  • For investors in Microsoft (MSFT), the direct financial impact is likely contained as the vulnerability spares the larger, strategic Microsoft 365 cloud business, though monitoring for any reputational fallout or costs associated with remediation is warranted.
  • This event reinforces the investment thesis for cybersecurity firms, especially those in endpoint detection, response, and network security, as enterprises will likely increase spending to defend against sophisticated, unpatched threats.
  • The significant business disruption caused by this vulnerability serves as a powerful catalyst for cloud migration, creating a long-term tailwind for cloud service providers and a headwind for companies dependent on on-premises software revenue.