PT-2025-28603 · Microsoft · Office Sharepoint +1
Published
2025-07-08
·
Updated
2025-07-22
·
CVE-2025-49706
7.5
High
Base vector | Vector | AV:N/AC:L/Au:S/C:C/I:P/A:N |
**Name of the Vulnerable Software and Affected Versions:**
Microsoft SharePoint Server (affected versions not specified)
Microsoft SharePoint Server Subscription Edition (affected versions not specified)
Microsoft SharePoint Foundation (affected versions not specified)
**Description:**
The issue involves improper authentication in Microsoft Office SharePoint, allowing an authorized attacker to perform spoofing over a network. The vulnerability enables attackers to bypass authentication on affected installations, potentially gaining unauthorized access to the system. Reports indicate a global cyberattack exploiting this vulnerability, compromising over 85 servers by July 20, 2025, utilizing malicious web shells and stolen `MachineKey` configurations for persistent access. The vulnerability is also referred to as a “ToolPane Authentication Bypass” and allows attackers to affect the system through data spoofing. Some reports suggest user interaction may be required for exploitation.
**Recommendations:**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Weakness Enumeration
Related Identifiers
Affected Products
References · 98
- https://bdu.fstec.ru/vul/2025-08524 · Security Note
- https://zerodayinitiative.com/advisories/ZDI-25-580 · Security Note
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706 · Vendor Advisory
- https://microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities · Vendor Advisory
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49706 · Security Note
- https://nvd.nist.gov/vuln/detail/CVE-2025-49706 · Security Note
- https://twitter.com/ntsuji/status/1947556888167793016 · Twitter Post
- https://reddit.com/r/CyberSecurity_NL/comments/1m5lkqc/security_updates_sharepoint_netscaler_en_cisco_ise · Reddit Post
- https://twitter.com/DarkAtlasSquad/status/1946930664428740967 · Twitter Post
- https://twitter.com/cglyer/status/1947646884971000255 · Twitter Post
- https://t.me/c/1197677768/2089 · Telegram Post
- https://twitter.com/SimoKohonen/status/1947171764871532894 · Twitter Post
- https://t.me/c/2275048697/117 · Telegram Post
- https://twitter.com/gothburz/status/1947165167319425378 · Twitter Post
- https://twitter.com/scp_localhost/status/1946766960328421490 · Twitter Post