Microsoft Patches Critical SharePoint Vulnerabilities Exploited by Chinese Hackers

6 Sources

Share

Microsoft has released patches for critical zero-day vulnerabilities in SharePoint that were actively exploited by Chinese state-sponsored hackers, affecting government agencies and organizations worldwide.

Critical SharePoint Vulnerabilities Discovered

Microsoft has recently patched critical zero-day vulnerabilities in its SharePoint server software that were actively exploited by Chinese state-sponsored hackers

1

. The vulnerabilities, designated as CVE-2025-53771 and CVE-2025-53770, affect only on-premises versions of SharePoint, leaving cloud-based SharePoint Online unaffected

2

.

Source: ZDNet

Source: ZDNet

Nature of the Vulnerabilities

CVE-2025-53771 is a SharePoint Server spoofing vulnerability, allowing attackers to impersonate trusted users or resources. CVE-2025-53770, rated as critical, is a remote code execution vulnerability that enables hackers to run code remotely in a SharePoint environment

2

. Together, these flaws allow cybercriminals to install malicious programs and compromise SharePoint environments.

Widespread Impact and Exploitation

The vulnerabilities have been exploited to attack various organizations, including US federal and state agencies, universities, and energy companies

3

. Alarmingly, even the US National Nuclear Security Administration was breached

4

. Microsoft has attributed the attacks to three Chinese nation-state actors: Linen Typhoon, Violet Typhoon, and Storm-2603

1

.

Ransomware Deployment

In a concerning development, Microsoft observed Storm-2603 deploying Warlock ransomware using these vulnerabilities. This ransomware strain not only encrypts data but also steals it, enabling double-extortion tactics

3

.

Microsoft's Response and Patch History

Source: Digit

Source: Digit

Microsoft initially attempted to fix the vulnerabilities with its July 8 Patch Tuesday updates. However, these patches proved insufficient, allowing hackers to bypass them

2

. The company has since released more robust protections, urging all users of on-premises SharePoint systems to install them immediately

5

.

Broader Implications

This incident occurs against a backdrop of increasing geopolitical tensions between the US and China, particularly in the tech sector. Reports suggest that major companies like Amazon and McKinsey are scaling back AI-related operations in China, while US officials intensify scrutiny of US companies working on AI in China

4

.

Recommendations for Organizations

Source: ZDNet

Source: ZDNet

Microsoft strongly advises all organizations using on-premises SharePoint servers to apply the latest security updates without delay. The company warns that delayed patching could leave systems vulnerable to expanding campaigns

5

. Additionally, Microsoft has published indicators of compromise and threat-hunting queries to assist defenders in identifying malicious activities

3

.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo