PT-2025-28603 · Microsoft · Office Sharepoint +1

Published

2025-07-08

·

Updated

2025-07-22

·

CVE-2025-49706

CVSS v2.0
7.5
VectorAV:N/AC:L/Au:S/C:C/I:P/A:N

**Name of the Vulnerable Software and Affected Versions:**

Microsoft SharePoint Server (affected versions not specified)

Microsoft SharePoint Server Subscription Edition (affected versions not specified)

Microsoft SharePoint Foundation (affected versions not specified)

**Description:**

The issue involves improper authentication in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over a network. The vulnerability enables attackers to bypass authentication on affected installations, potentially gaining unauthorized access to the system. Reports indicate a global cyberattack exploiting this vulnerability, compromising over 85 servers by July 20, 2025, utilizing malicious web shells and stolen `MachineKey` configurations for persistent access. The vulnerability is also referred to as a “ToolPane Authentication Bypass” and allows attackers to affect the system through data spoofing. Some reports suggest user interaction may be required for exploitation.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-08524
CVE-2025-49706
ZDI-25-580

Affected Products

Office Sharepoint
Sharepoint Server