Microsoft has issued an urgent security advisory for on-premises SharePoint Server customers in response to active exploitation of a critical remote code execution (RCE) vulnerability. The issueβnow tracked as CVE-2025-53770 with a CVSS score of 9.8βis being used in the wild by threat actors and presents a serious risk to unpatched systems.
βMicrosoft is aware of active attacks targeting on-premises SharePoint Server customers. The attacks are exploiting a variant of CVE-2025-49706,β the guidance states.
The flaw exists in the way on-premises SharePoint Server handles deserialization of untrusted data, allowing unauthenticated attackers to execute arbitrary code remotely over a network.
βDeserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network,β the advisory explains.
This critical vulnerability does not affect SharePoint Online, as confirmed by Microsoft.
As of now, no security update is available, but Microsoft is actively working on a fix.
βMicrosoft is preparing and fully testing a comprehensive update to address this vulnerability. This page will be updated when an update is available.β
In the meantime, Microsoft has provided mitigation steps to help protect systems from exploitation:
- Enable AMSI integration in SharePoint Server.
- Deploy Microsoft Defender Antivirus across all SharePoint servers.
- Disconnect the server from the internet if AMSI cannot be enabled.
βIf enabling AMSI is not an option, you should remove access to the internet from the SharePoint server. These two options protect from unauthenticated attacks,β the advisory recommends.
Microsoft Defender Antivirus and Defender for Endpoint can detect post-exploitation activity using several detection names:
- Exploit:Script/SuspSignoutReq.A
- Trojan:Win32/HijackSharePointServer.A
Related alerts in the Microsoft Defender Security Center include:
- Possible web shell installation
- Possible exploitation of SharePoint server vulnerabilities
- Suspicious IIS worker process behavior
- βSuspSignoutReqβ malware was blocked on a SharePoint server
- HijackSharePointServerβ malware was blocked on a SharePoint server
Microsoft has also released a KQL (Kusto Query Language) script for advanced hunting. The query searches for the creation of spinstall0.aspx, a telltale sign of successful post-exploitation:
Update
Customers using SharePoint 2016 or 2019 should follow the guidance below.
- Use or upgrade to supported versions of on-premises Microsoft SharePoint Server
- Supported versions: SharePoint Server 2016, 2019, & SharePoint Subscription Edition
- Apply the latest security updates
- Latest update: July 2025 Security Update
| Product | KB Article | Security Update | Fixed Build Number |
| Microsoft SharePoint Server 2019 | 5002741 | Security Update | 16.0.10417.20027 |
| Microsoft SharePoint Enterprise Server 2016 | 5002744 | Security Update | 16.0.5508.1000 |
- Ensure theΒ Antimalware Scan InterfaceΒ is turned on and configured correctly
Related Posts:
- Microsoft’s September Patch Tuesday: A Patchwork of Urgency with 4 Zero-Days Under Attack
- Microsoft Raises Server Prices: 10% Increase Coming
- CVE-2024-38094 Exploited: Attackers Gain Domain Access via Microsoft SharePoint Server
- Microsoft Enhances Exchange and SharePoint Security with AMSI Integration
- SharePoint Shadow: Havoc’s FUD Malware Conceals Cyber Attacks
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.