"SharePoint Vulnerabilities: Alberta Urges Immediate Action"

This title was summarized by AI from the post below.

🚨 Critical SharePoint Vulnerabilities Actively Exploited – Immediate Action Required ‼️Alberta's cyber threat landscape around Microsoft SharePoint has escalated significantly, with three CVEs now confirmed — two with available patches and one actively exploited zero-day with no patch yet released.

View organization page for CyberAlberta

4,551 followers

🚨 Critical SharePoint Vulnerabilities Actively Exploited – Immediate Action Required ‼️Alberta's cyber threat landscape around Microsoft SharePoint has escalated significantly, with three CVEs now confirmed — two with available patches and one actively exploited zero-day with no patch yet released. 🔍 Summary of CVEs and Key Actions: 1️⃣CVE-2025-49704 – Remote Code Execution (RCE) 💡IOCs: Suspicious PowerShell from w3wp.exe, unfamiliar outbound connections, webshell artifacts in SharePoint directories, modified ASPX pages with embedded scripts or obfuscated code. ⚡Mitigation: Apply patch KB5002744, monitor SharePoint logs for further activity, audit site-member permissions, use EDR tools to detect PowerShell misuse and lateral movement. 2️⃣CVE-2025-49706 – Spoofing Vulnerability 💡IOCs: Use of forged tokens or manipulated SAML requests, impersonation of privileged users, abnormal access to sensitive SharePoint resources. Unexpected changes to user permissions and or group memberships. ⚡Mitigation: Apply patch KB5002744 (2016) or patch KB5002741 (2019), enable multi-factor authentication, audit SharePoint roles and permissions. 3️⃣CVE-2025-53770 – Zero-Day RCE via .NET Deserialization No patch available. 💡IOCs: Webshells in SharePoint accessible directories, suspicious HTTP POST requests, unexpected file creation or modification, outbound connections to attacker C2 infrastructure, suspicious w3wp.exe IIS worker processes. ⚡Mitigation: Enable AMSI (Anti-malware Scan Interface) integration if possible. Deploy Microsoft Defender Anti-virus & EDR. Strongly consider disconnecting internet-facing SharePoint servers. Monitor for known IOCs and use advanced hunting in Microsoft 365 Defender. ‼️Canadian Centre for Cyber Security (CCCS) has issued alert AL25-009 regarding CVE-2025-53770: https://lnkd.in/eXMDC-dU 🔗 CVE References (NIST): https://lnkd.in/guqMeHXE https://lnkd.in/gKgqZNpM https://lnkd.in/dgWmbAPP #CyberAlberta #InfoSec #SharePoint #ThreatIntel #IncidentResponse #CVE2025 #CyberSecurity

  • No alternative text description for this image

To view or add a comment, sign in

Explore content categories