A week after Microsoft told the world that its July software updates didn't fully fix a couple of bugs, which allowed miscreants to take over on-premises SharePoint servers and remotely execute code, researchers have assembled much of the puzzle — with one big missing piece. How did the attackers, who include Chinese government spies, data thieves, and ransomware operators, know how to exploit the SharePoint CVEs in such a way that would bypass the security fixes Microsoft released the following day? "A leak happened here somewhere," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative (ZDI), told The Register. "And now you've got a zero-day exploit in the wild, and worse than that, you've got a zero-day exploit in the wild that bypasses the patch, which came out the next day." It all began back in May, on stage at the Pwn2Own competition. Pwn2Own is the hackers' equivalent of the World Series, and ZDI usually hosts these competitions twice a year. The most recent contest occurred in Berlin, beginning May 15. On day 2 of the event, Vietnamese researcher Dinh Ho Anh Khoa combined an auth bypass and an insecure deserialization bug to exploit Microsoft SharePoint and win $100,000. "What happens on the stage is just one part of Pwn2Own," Childs said. After demonstrating a successful exploit, the bug hunter and vendor are whisked away into a private room where the researcher explains what they did and provides the technology company with a full write-up of ...
Blame a leak for Microsoft SharePoint attacks: researcher
The Register
·Jessica Lyons
·Published Jul 26, 2025
·Updated
Affected Software
1 affected component
Microsoft SharePoint
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the security risks associated with Microsoft SharePoint due to vulnerabilities that remain unpatched after recent software updates.
2
What security implications are discussed in the article?
The article highlights how unpatched issues in SharePoint can lead to remote code execution and potential takeovers of on-premises servers.
3
What products or software are affected by the vulnerabilities mentioned?
The vulnerabilities primarily affect Microsoft SharePoint servers.
4
What should organizations using SharePoint do in response to this news?
Organizations should ensure they apply all available security updates and monitor their SharePoint servers for any unusual activity.
5
What prompted the renewed attention to Microsoft SharePoint's vulnerabilities?
Researchers discovered that the July software updates did not fully address the existing vulnerabilities, allowing ongoing exploitation.