CVE-2025-53771General(microsoft / sharepoint_server)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharepoint_server

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-10-02); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
sharepoint_server

2 versions affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-04: 1Mentions · 2026-10-01: 1Mentions · 2026-10-02: 2Mentions · 2026-10-04: 104-0410-0110-0210-04
Signal classification1 categories
General
1100.0%
Referenced assets9 URLs
Full discourse5 posts
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE CAMPAIGN HITS WATER AND TELECOM OPERATORS THROUGH SHAREPOINT October 1, 2026 DISCLOSED BY: Symantec / Carbon Black CONFIRMED EXPLOITED BY: Symantec / Carbon Black PRODUCT: Microsoft SharePoint Server — On-Premises CVE: Multiple SharePoint vulnerabilities are used across the campaign. Historically associated ToolShell flaws include CVE-2025-49704, CVE-2025-49706, CVE-2025-53770 and CVE-2025-53771. IMPACT: Symantec documented a recent Warlock campaign compromising at least four organizations, including a water utility and telecommunications provider, plus a regional government body and university. In one critical-infrastructure intrusion, attackers disabled security tooling on at least 40 hosts in roughly two hours and deployed Warlock ransomware to at least 33 systems through the domain SYSVOL share. EXPLOITATION STATUS: CONFIRMED OPERATIONAL RANSOMWARE CAMPAIGN CISA records knownRansomwareCampaignUse: Known for the core ToolShell KEV entries CVE-2025-49704, CVE-2025-49706 and CVE-2025-53770. The exact SharePoint CVE used for every recent intrusion has NOT been established. Attribution: Symantec tracks the actor as Longlegs, also associated with Storm-2603, and assesses it as China-nexus. This is NOT a formal government attribution to the Chinese state. Forensic triage: Hunt for SharePoint LAYOUTS web shells, stolen http://ASP.NET machine keys, K7RKScan/BYOVD activity, Visual Studio Code tunnels, NetExec, suspicious SYSVOL payloads and domain-wide ransomware staging. URGENT ACTION: Patch all on-premises SharePoint servers. Previously exposed systems require compromise assessment, http://ASP.NET machine-key rotation, credential review, and hunting across SYSVOL and domain controllers; patching alone does not establish that the environment is clean. SOURCE: https://www.security.com/threat-intelligence/warlock-ransomware-critical-infrastructure CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the campaign, victim scope and observed post-exploitation behavior based on direct Symantec/Carbon Black investigations. The China-nexus attribution is a vendor intelligence assessment, not a formal government attribution. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #ToolShell #Warlock #Storm2603 #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics

    00010137
    227 followersView on X
  • SecureChap@SecureChap

    Warlock ransomware operators chained four SharePoint CVEs for domain access on July 22. Unspecified on-prem builds were hit with CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771 via ToolShell. Microsoft linked the same chain to Linen Typhoon, Violet Typhoon, and Storm-2603. Within two hours the operators dropped an AV/EDR killer to 40 hosts via BYOVD. They abused the signed K7RKScan.sys driver through CVE-2025-1055 to load a malicious kernel module and disable protections, then deployed a multi-version SharePoint web shell for persistence. NetExec handled AD enumeration and spraying while VS Code Insiders ran as a service for tunneling. Ransomware binaries were staged in the domain SYSVOL share for GPO and logon script distribution. Artifacts were deleted two days later. Warlock executed on 33 hosts by July 31 against a water utility, telecom provider, regional government, and university in Portuguese- and Spanish-speaking regions. Symantec attributes the activity to Longlegs. BYOVD via K7RKScan plus SYSVOL staging turned SharePoint access into domain-wide execution in under ten days.

    0000062
    175 followersView on X
  • ♫Why♥Not♪@Python_s_

    🚨 #ALERT — WARLOCK RANSOMWARE ACTORS CONTINUE EXPLOITING SHAREPOINT, HITTING WATER AND TELECOM OPERATORS October 1, 2026 DISCLOSED BY: Symantec / Broadcom Threat Hunter Team CONFIRMED EXPLOITED BY: Longlegs / Storm-2603 PRODUCT: Microsoft SharePoint Server — On-Premises CVE: No single CVE is publicly confirmed for every recent intrusion. Historically associated ToolShell chain: CVE-2025-49704 CVE-2025-49706 CVE-2025-53770 CVE-2025-53771 IMPACT: SharePoint exploitation → web shell → http://ASP.NET Machine Key theft → code execution → lateral movement → AV/EDR disruption → domain-scale Warlock ransomware deployment. EXPLOITATION STATUS: CONFIRMED ACTIVE EXPLOITATION CONFIRMED RANSOMWARE DEPLOYMENT CRITICAL-INFRASTRUCTURE VICTIMS CONFIRMED Forensic triage: Hunt for SharePoint LAYOUTS web shells, Machine Key theft, new privileged accounts, VS Code Tunnel services, BYOVD activity and ransomware/SYSVOL staging. URGENT ACTION: Fully patch on-prem SharePoint. Rotate http://ASP.NET Machine Keys on exposed or suspected systems and restart IIS. Investigate previously vulnerable systems before treating them as clean. SOURCE: https://www.security.com/blog-post/warlock-ransomware-critical-infrastructure EXPLOITATION UPDATE: Symantec observed at least four recent victims: a water utility, telecom operator, regional government body and university across Europe, Africa and Latin America. In one intrusion, an AV/EDR-killing tool reached 40+ hosts and Warlock ransomware was deployed to at least 33 hosts using SYSVOL replication. SUPPORTING SOURCE: https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ CONFIDENCE: VERY HIGH — direct Symantec/Broadcom incident telemetry. HIGH — Longlegs/Storm-2603 attribution is consistent with prior Microsoft reporting. #CyberSecurity #ThreatIntel #NØØT #Microsoft #SharePoint #Warlock #Ransomware #ActiveExploitation #CriticalInfrastructure #IncidentResponse #DigitalForensics #Storm2603

    00000116
    227 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2025-53771 Product: Microsoft / SharePoint Summary: VulnCheck reports real-world exploitation activity affecting Microsoft / SharePoint. Evidence: Ransomware use confirmed; Active exploitation reported; Severe impact class Impact: The vulnerability is associated with ransomware activity and may contribute to compromise of exposed systems. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 18 Jul 2025 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Microsoft #SharePoint #CVE_2025_53771 #ActiveExploitation #Exploit #Ransomware #RansomwareAttack

    0000060
    226 followersView on X
  • Cliff Vazquez@cliffvazquez
    General

    Proactive Security for CVE-2025-53770 and CVE-2025-53771 SharePoint Attacks - http://www.trendmicro.com https://news.google.com/rss/articles/CBMiqAFBVV95cUxOMDdQUkkzODNSYkpXcXFBUGR6aFFXRlNRY2NiMUZzRWtSZG1ybUlZM3YwZE5UR1RkSXZUbkllWnpIWWtqQ2lrMWNoZ3JrSzVTRU4zc1ZoWGxlNXVTNm5JX0xxMFRMMTlFVU9UWWpiVHlzZmtHY093cXdNaTZ6NlNLRXEyWHctUk9mVFpXU2hBaGpEa3JDN0hlUVRqRlp6RTZoaGRRZ2xJS2M?oc=5 #technology #cybersecurity https://t.co/KJPNQ5SdV4

    Post summary

    The message only mentions the CVE identifiers and provides a link to a Trend Micro article but lacks any technical or actionable details.

    00000275
    1.3K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsharepoint_server---
Appmicrosoftsharepoint_server2016--
Appmicrosoftsharepoint_server2019--

Explore more