{"id":123220,"date":"2025-07-21T08:10:35","date_gmt":"2025-07-21T07:10:35","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=123220"},"modified":"2025-07-21T08:29:39","modified_gmt":"2025-07-21T07:29:39","slug":"assume-breach-critical-sharepoint-flaws-under-mass-attack-warns-unit-42","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2025\/07\/21\/assume-breach-critical-sharepoint-flaws-under-mass-attack-warns-unit-42\/","title":{"rendered":"Assume breach: Critical SharePoint flaws under mass attack, warns Unit 42"},"content":{"rendered":"\n<p>Microsoft has released emergency out-of-band patches to fix two high-severity remote code execution (RCE) vulnerabilities in SharePoint Server, after both flaws were discovered to be actively exploited in the wild.<\/p>\n\n\n\n<p>The vulnerabilities &#8211; CVE-2023-29357 and CVE-2023-24955 enable attackers to bypass authentication and gain elevated privileges on vulnerable on-premises Microsoft SharePoint servers. The implications are far-reaching, as SharePoint serves as a central hub for file sharing, collaboration, and data storage across government agencies, educational institutions, healthcare providers, and large enterprises.<\/p>\n\n\n\n<p>Microsoft\u2019s security bulletin classified the flaws as critical, urging customers to apply updates immediately. But experts say patching alone may not be enough to mitigate the full extent of the threat.<\/p>\n\n\n\n<p>In a statement to the press, Michael Sikorski, CTO and Head of Threat Intelligence for Unit 42 at Palo Alto Networks, revealed the scale and sophistication of the campaign now underway:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cUnit 42 is tracking a high-impact, ongoing threat campaign targeting on-premises Microsoft SharePoint servers. While cloud environments remain unaffected, on-prem SharePoint deployments, particularly within government, schools, healthcare, including hospitals, and large enterprise companies, are at immediate risk.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>Sikorski warned that attackers are successfully bypassing identity protections such as multi-factor authentication (MFA) and single sign-on (SSO), and are moving laterally across networks to exfiltrate sensitive data, steal cryptographic keys, and establish persistent backdoors.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cIf you have SharePoint on-prem exposed to the internet, you should assume that you have been compromised at this point. Patching alone is insufficient to fully evict the threat.\u201d<\/p>\n<\/blockquote>\n\n\n\n<p>According to Microsoft, the attackers are using a previously disclosed authentication bypass (CVE-2023-29357) to gain administrator privileges, which is then chained with an RCE vulnerability (CVE-2023-24955) to execute arbitrary code remotely. This chained exploit was demonstrated by StarLabs SG at Pwn2Own Vancouver 2023, and now appears to be deployed in real-world attacks.<\/p>\n\n\n\n<p>Sikorski emphasised the systemic risk posed by SharePoint\u2019s deep integration across Microsoft services, including Office, Teams, OneDrive and Outlook, making a single breach capable of triggering a widespread compromise.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>\u201cA compromise doesn\u2019t stay contained \u2013 it opens the door to the entire network,\u201d he said. \u201cThis is a high-severity, high-urgency threat. We are urging organisations who are running on-prem SharePoint to take action immediately.\u201d<\/p>\n\n\n\n<p>While Microsoft has released patches, experts warn that immediate response measures are still necessary:<\/p>\n<\/blockquote>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Disconnect vulnerable SharePoint servers from the internet.<\/li>\n\n\n\n<li>Apply all available Microsoft patches immediately.<\/li>\n\n\n\n<li>Rotate all cryptographic keys and certificates<strong>.<\/strong><\/li>\n\n\n\n<li>Engage with professional incident response teams to assess scope of compromise.<\/li>\n<\/ul>\n\n\n\n<p>\u201cAn immediate, band-aid fix would be to unplug your Microsoft SharePoint from the internet until a patch is available. A false sense of security could result in prolonged exposure and widespread compromise,\u201d Sikorski warned.<\/p>\n\n\n\n<p>Microsoft is continuing to coordinate with cybersecurity partners, including Palo Alto Networks and others, to monitor the campaign and issue additional protections.<\/p>\n\n\n\n<p>For organisations reliant on SharePoint, especially those in regulated industries such as healthcare and public services, this incident is a reminder that default on-premises deployments are no longer a safe option without constant patching and layered defences.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has released emergency out-of-band patches to fix two high-severity remote code execution (RCE) vulnerabilities in SharePoint Server, after both flaws were discovered to be actively exploited in the wild. The vulnerabilities &#8211; CVE-2023-29357 and CVE-2023-24955 enable attackers to bypass authentication and gain elevated privileges on vulnerable on-premises Microsoft SharePoint servers. The implications are far-reaching, [&hellip;]<\/p>\n","protected":false},"author":4338,"featured_media":100799,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14804,19391,13],"tags":[1530,20010,10],"class_list":["post-123220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-hot-topic","category-top-stories","tag-cybersecurity","tag-microsoft-sharepoint","tag-security-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/4338"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=123220"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123220\/revisions"}],"predecessor-version":[{"id":123221,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/123220\/revisions\/123221"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/100799"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=123220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=123220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=123220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}