Microsoft SharePoint Zero-Day
中国黑客利用微软SharePoint高危漏洞CVE-2025-53770(评分9.8)窃取全球数据。该漏洞允许未认证远程访问暴露于互联网的SharePoint服务器。研究人员警告此漏洞被活跃利用,影响内部部署服务器,但不影响微软云服务如SharePoint Online和Microsoft 365。 2025-7-28 11:9:22 Author: www.schneier.com(查看原文) 阅读量:22 收藏

Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide:

The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the vulnerability, which affects SharePoint Servers that infrastructure customers run in-house. Microsoft’s cloud-hosted SharePoint Online and Microsoft 365 are not affected.

Here’s Microsoft on patching instructions. Patching isn’t enough, as attackers have used the vulnerability to steal authentication credentials. It’s an absolute mess. CISA has more information. Also these four links. Two Slashdot threads.

This is an unfolding security mess, and quite the hacking coup.

Tags: , , , ,

Posted on July 28, 2025 at 7:09 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/07/microsoft-sharepoint-zero-day.html
如有侵权请联系:admin#unsafe.sh